Description
Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 pypi | | =0.2 || =1.0 || =1.1 || =1.1.1 || =1.2 || =1.2.1 || =2.0 || =2.1 || =2.1.1 || =2.2 || =2.2.1 || =2.3 || =2.4 || =2.4.1 || =3.0 || =3.0.1 || =3.0.2 || =3.1 || =3.1.1 || =3.2 || =3.2.1 || =3.2.2 || =4.0 || =4.0.1 || =4.0.2 || =4.1 || =4.1b2 || =4.2 || =4.2.1 || =4.2b1 || =4.3 || =4.3b1 || =4.3b2 || =4.4 || =4.4.1 || =4.4.2 || =4.4.3 || =4.4b1 || =4.5 || =4.5.1 || =4.5.2 || =4.5.3 || =4.5b1 || =4.5b2 || =5.0 || =5.0.1 || =5.0.2 || =5.0a1 || =5.0b1 || =5.1 || =5.1.1 || =5.1b1 || =6.0 || =6.0.1 || =6.0.2 || =6.0.3 || =6.0.4 || =6.0a1 || =6.0b1 || =6.1 || =6.1b1 || =6.1b2 || =6.2 || =6.2b1 || =6.2b2 || =6.3 || =6.3.1 || =6.3.2 || =6.3b1 || >=0 <6.3.3 | 6.3.3 |
 debian 14 | | | 6.4.0-1 |
 debian 12 | | =6.2.0-3 || =6.2.0-3+deb12u1 || =6.2.0-3+deb12u2 || =6.2.0-3+deb12u3 || =6.2.0-3+deb12u4 || =6.3.2-1 || =6.4.0-1 || =6.4.0-2 || =6.4.1-1 || =6.4.1-2 || =6.4.1-3 || =6.4.2-1 || =6.4.2-2 || =6.4.2-3 || =6.5.2-1 || =6.5.2-2 || =6.5.2-3 || =6.5.4-0.1 || =6.5.4-1 || =6.5.5-1 || =6.5.5-2 || =6.5.5-3 || =6.5.5-4 || =6.5.5-5 | - |
 debian 13 | | | 6.4.0-1 |