Tornado
cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*
- <= 6.5.4
A cookie attribute injection vulnerability exists in Tornado versions prior to 6.5.5. The issue arises because the domain, path, and samesite arguments in the .RequestHandler.set_cookie method were not properly validated, allowing crafted characters to be injected. This could be exploited to manipulate other attributes of the cookie.
Exploitation of this vulnerability could lead to injection of attacker-controlled values into cookie attributes, potentially allowing for manipulation of cookie behavior or security.
Users can upgrade to Tornado version 6.5.5 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.