Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fqwm-6jpj-5wxc

Опубликовано: 03 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Tornado has cookie attribute injection via .RequestHandler.set_cookie

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

Пакеты

Наименование

tornado

pip
Затронутые версииВерсия исправления

< 6.5.5

6.5.5

EPSS

Процентиль: 15%
0.00237
Низкий

7.2 High

CVSS3

Дефекты

CWE-159

Связанные уязвимости

CVSS3: 7.2
ubuntu
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 5.4
redhat
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
nvd
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
debian
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur becaus ...

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость веб-фреймворка и асинхронной сетевой библиотеки Tornado, связанная с некорректной обработкой специальных элементов, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 15%
0.00237
Низкий

7.2 High

CVSS3

Дефекты

CWE-159