{"id":"GHSA-8vpw-mgpf-mpvv","summary":"Tornado XSRF cookie allows side-channel attack against TLS (BREACH attack)","details":"Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.","aliases":["CVE-2014-9720","PYSEC-2020-213"],"modified":"2024-11-13T23:03:25.435873Z","published":"2022-05-17T19:57:19Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-02-01T20:53:42Z","nvd_published_at":"2020-01-24T18:15:00Z","cwe_ids":["CWE-203"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-9720"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/1c36307463b1e8affae100bf9386948e6c1b2308"},{"type":"WEB","url":"https://bugzilla.novell.com/show_bug.cgi?id=930362"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1222816"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2020-213.yaml"},{"type":"PACKAGE","url":"https://github.com/tornadoweb/tornado"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/05/19/4"},{"type":"WEB","url":"http://www.tornadoweb.org/en/stable/releases/v3.2.2.html"}],"affected":[{"package":{"name":"tornado","ecosystem":"PyPI","purl":"pkg:pypi/tornado"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.2"}]}],"versions":["0.2","1.0","1.1","1.1.1","1.2","1.2.1","2.0","2.1","2.1.1","2.2","2.2.1","2.3","2.4","2.4.1","3.0","3.0.1","3.0.2","3.1","3.1.1","3.2","3.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-8vpw-mgpf-mpvv/GHSA-8vpw-mgpf-mpvv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}