PT-2021-11540 · Tornado · Tornado
Published
2021-01-18
·
Updated
2021-02-15
·
CVE-2020-28476
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
tornado (affected versions not specified)
Description:
The issue allows for Web Cache Poisoning through a technique called parameter cloaking. An attacker can exploit this by separating query parameters using a semicolon (;), causing a difference in how the request is interpreted between the proxy and the server. This can lead to malicious requests being cached as if they were safe, because the proxy does not see the semicolon as a separator and thus does not include it in the cache key for an unkeyed parameter.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tornado