VDB
KO

PYSEC-2020-213

Details

Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / tornado
Introduced in: 0 Fixed in: 1c36307463b1e8affae100bf9386948e6c1b2308
Fix pip install --upgrade 'tornado>=1c36307463b1e8affae100bf9386948e6c1b2308'

References