Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-35536

Опубликовано: 03 апр. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.2

Описание

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

РелизСтатусПримечание
devel

needed

esm-apps/bionic

released

4.5.3-1ubuntu0.2+esm3
esm-apps/focal

released

6.0.3+really5.1.1-3ubuntu0.1~esm5
esm-apps/jammy

released

6.1.0-3ubuntu0.1~esm5
esm-infra-legacy/xenial

released

4.2.1-1ubuntu3.1+esm3
esm-infra/xenial

released

4.2.1-1ubuntu3.1+esm3
jammy

needed

noble

released

6.4.0-1ubuntu0.5
questing

released

6.4.2-3ubuntu0.3
resolute

released

6.5.4-0.1ubuntu0.1

Показывать по

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
nvd
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
debian
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur becaus ...

CVSS3: 7.2
github
4 месяца назад

Tornado has cookie attribute injection via .RequestHandler.set_cookie

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость веб-фреймворка и асинхронной сетевой библиотеки Tornado, связанная с некорректной обработкой специальных элементов, позволяющая нарушителю выполнить произвольный код

7.2 High

CVSS3