Vulnerability Details CVE-2014-9720
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.8%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2014-9720
-
cpe:2.3:a:tornadoweb:tornado:1.0
-
cpe:2.3:a:tornadoweb:tornado:1.0.1
-
cpe:2.3:a:tornadoweb:tornado:1.1
-
cpe:2.3:a:tornadoweb:tornado:1.1.1
-
cpe:2.3:a:tornadoweb:tornado:1.2
-
cpe:2.3:a:tornadoweb:tornado:1.2.1
-
cpe:2.3:a:tornadoweb:tornado:2.0
-
cpe:2.3:a:tornadoweb:tornado:2.1
-
cpe:2.3:a:tornadoweb:tornado:2.1.1
-
cpe:2.3:a:tornadoweb:tornado:2.2
-
cpe:2.3:a:tornadoweb:tornado:2.2.1
-
cpe:2.3:a:tornadoweb:tornado:2.3.0
-
cpe:2.3:a:tornadoweb:tornado:2.4.0
-
cpe:2.3:a:tornadoweb:tornado:2.4.1
-
cpe:2.3:a:tornadoweb:tornado:3.0.0
-
cpe:2.3:a:tornadoweb:tornado:3.0.1
-
cpe:2.3:a:tornadoweb:tornado:3.0.2
-
cpe:2.3:a:tornadoweb:tornado:3.1.0
-
cpe:2.3:a:tornadoweb:tornado:3.1.1
-
cpe:2.3:a:tornadoweb:tornado:3.2.0
-
cpe:2.3:a:tornadoweb:tornado:3.2.1