Tornado XSRF cookie allows side-channel attack against TLS (BREACH attack)
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Nov 13, 2024
Description
Published by the National Vulnerability Database
Jan 24, 2020
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Feb 1, 2024
Last updated
Nov 13, 2024
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
References