Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-9720
Description:Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2015.0251   1.3.6.1.4.1.25623.1.0.869438   1.3.6.1.4.1.25623.1.0.869612   1.3.6.1.4.1.25623.1.1.1.2.2015.279   1.3.6.1.4.1.25623.1.1.1.2.2016.475  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-9720
http://openwall.com/lists/oss-security/2015/05/19/4
http://www.tornadoweb.org/en/stable/releases/v3.2.2.html
https://bugzilla.novell.com/show_bug.cgi?id=930362
https://bugzilla.redhat.com/show_bug.cgi?id=1222816
https://github.com/tornadoweb/tornado/commit/1c36307463b1e8affae100bf9386948e6c1b2308




© 1998-2025 E-Soft Inc. All rights reserved.