PT-2021-11540 · Tornado · Tornado

Published

2021-01-18

·

Updated

2021-02-15

·

CVE-2020-28476

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: tornado (affected versions not specified)
Description: The issue allows for Web Cache Poisoning through a technique called parameter cloaking. An attacker can exploit this by separating query parameters using a semicolon (;), causing a difference in how the request is interpreted between the proxy and the server. This can lead to malicious requests being cached as if they were safe, because the proxy does not see the semicolon as a separator and thus does not include it in the cache key for an unkeyed parameter.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-28476

Affected Products

Tornado