Lack of data validation In python-tornado
Description
Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
pypi | 6.5.8 | ||
debian 12 | - | ||
debian 14 | - | ||
rpm rhel10 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - | |
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
rpm rhel10 | - | - | |
rpm rhel9 | - | - |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6.