Описание
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
A flaw was found in Tornado's CurlAsyncHTTPClient component. This vulnerability, known as CRLF (Carriage Return Line Feed) injection, occurs because the client fails to properly reject carriage return and line feed characters in HTTP request headers. A remote attacker can exploit this by injecting these characters into header values, allowing them to inject arbitrary headers or construct entirely new HTTP requests. This could potentially lead to server-side request forgery (SSRF) vulnerabilities.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Out of support scope | ||
| Lightspeed Core | lightspeed-core/lightspeed-stack-rhel9 | Fix deferred | ||
| Lightspeed Core | lightspeed-core/rag-tool-cpu-rhel9 | Fix deferred | ||
| Lightspeed Core | lightspeed-core/rag-tool-cuda-12.9-rhel9 | Fix deferred | ||
| Migration Toolkit for Applications 8 | mta/mta-solution-server-rhel9 | Out of support scope | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-ocp-rag-rhel9 | Fix deferred | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-chatbot-rhel9 | Fix deferred | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-27/lightspeed-chatbot-rhel9 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | python-tornado | Fix deferred | ||
| Red Hat Enterprise Linux 10 | rhel10/keylime-registrar | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
(Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAs ...)
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAs ...
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
EPSS
5.4 Medium
CVSS3