logo

Database

Lack of data validation - Special Characters In tornado

Description

Tornado has cookie attribute injection via .RequestHandler.set_cookie In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

1-10 of 12

10

FLAT-E0DM5 – Vulnerability | Fluid Attacks Database