Safety vulnerability ID: 54090
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
Latest version: 6.4.2
Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application