Описание
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| python-tornado | fixed | 6.5.5-1 | package | |
| python-tornado | no-dsa | trixie | package |
Примечания
https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7
Fixed by: https://github.com/tornadoweb/tornado/commit/24a2d96ea115f663b223887deb0060f13974c104 (v6.5.5)
EPSS
Связанные уязвимости
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
Tornado has cookie attribute injection via .RequestHandler.set_cookie
Уязвимость веб-фреймворка и асинхронной сетевой библиотеки Tornado, связанная с некорректной обработкой специальных элементов, позволяющая нарушителю выполнить произвольный код
EPSS