PT-2026-29974 · Tornado+4 · Tornado+4
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tornado versions prior to 6.5.5
Description
Prior to version 6.5.5, Tornado is susceptible to cookie attribute injection due to insufficient validation of the domain, path, and samesite arguments when setting cookies using
.RequestHandler.set cookie. This could allow for crafted characters to be injected into these attributes.Recommendations
Update to Tornado version 6.5.5 or later.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Tornado
Ubuntu