![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2014-9720 |
Description: | Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests. |
Test IDs: | 1.3.6.1.4.1.25623.1.1.10.2015.0251 1.3.6.1.4.1.25623.1.0.869438 1.3.6.1.4.1.25623.1.0.869612 1.3.6.1.4.1.25623.1.1.1.2.2015.279 1.3.6.1.4.1.25623.1.1.1.2.2016.475 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2014-9720 http://openwall.com/lists/oss-security/2015/05/19/4 http://www.tornadoweb.org/en/stable/releases/v3.2.2.html https://bugzilla.novell.com/show_bug.cgi?id=930362 https://bugzilla.redhat.com/show_bug.cgi?id=1222816 https://github.com/tornadoweb/tornado/commit/1c36307463b1e8affae100bf9386948e6c1b2308 |