Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 PyPI

Tornado XSRF cookie allows side-channel attack against TLS (BREACH attack)

GHSA-8vpw-mgpf-mpvv · CVE-2014-9720 · PYSEC-2020-213

Published · Modified

Description

Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

Ready to move

Start Securing

Free, no credit card | First findings in minutes