Количество 5
Количество 5
CVE-2024-58384
(Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAs ...)
CVE-2024-58384
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
CVE-2024-58384
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
CVE-2024-58384
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAs ...
GHSA-qf37-5gqv-7f3m
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-58384 (Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAs ...) | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
CVE-2024-58384 Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests. | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
CVE-2024-58384 Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests. | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
CVE-2024-58384 Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAs ... | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
GHSA-qf37-5gqv-7f3m Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests. | CVSS3: 5.4 | 0% Низкий | 4 дня назад |
Уязвимостей на страницу