Описание
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
Уязвимые конфигурации
EPSS
7.2 High
CVSS3
5.3 Medium
CVSS3
Дефекты
Связанные уязвимости
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
In Tornado before 6.5.5, cookie attribute injection could occur becaus ...
Tornado has cookie attribute injection via .RequestHandler.set_cookie
EPSS
7.2 High
CVSS3
5.3 Medium
CVSS3