Vulnerabilities
Vulnerable Software
Tornadoweb:  >> Tornado  >> 2.4.0  Security Vulnerabilities
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
CVSS Score
6.1
EPSS Score
0.004
Published
2023-05-25
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
CVSS Score
6.5
EPSS Score
0.009
Published
2020-01-24


Contact Us

Shodan ® - All rights reserved