Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.1
CVE-2023-28370
- EPSS 1.14%
- Veröffentlicht 25.05.2023 10:15:09
- Zuletzt bearbeitet 03.11.2025 22:16:06
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
6.5
CVE-2014-9720
- EPSS 2.51%
- Veröffentlicht 24.01.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 02:21:31
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
- EPSS 1.37%
- Veröffentlicht 23.05.2012 20:55:01
- Zuletzt bearbeitet 16.06.2026 23:41:26
CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.