Candidate: CVE-2014-9720 PublicDate: 2020-01-24 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9720 http://www.openwall.com/lists/oss-security/2015/05/19/4 Description: Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests. Ubuntu-Description: Notes: Bugs: https://bugzilla.novell.com/show_bug.cgi?id=930362 https://bugzilla.redhat.com/show_bug.cgi?id=1222816 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N [6.5 MEDIUM] Patches_python-tornado: upstream: https://github.com/tornadoweb/tornado/commit/1c36307463b1e8affae100bf9386948e6c1b2308 upstream_python-tornado: released (3.2.2) precise_python-tornado: ignored (reached end-of-life) precise/esm_python-tornado: DNE (precise was needed) trusty_python-tornado: ignored (reached end-of-life) trusty/esm_python-tornado: DNE (trusty was needed) utopic_python-tornado: ignored (reached end-of-life) vivid_python-tornado: ignored (reached end-of-life) vivid/stable-phone-overlay_python-tornado: DNE vivid/ubuntu-core_python-tornado: DNE wily_python-tornado: ignored (reached end-of-life) xenial_python-tornado: not-affected (3.2.2-1) esm-infra/xenial_python-tornado: not-affected (3.2.2-1) yakkety_python-tornado: ignored (reached end-of-life) zesty_python-tornado: ignored (reached end-of-life) artful_python-tornado: ignored (reached end-of-life) bionic_python-tornado: not-affected (3.2.2-1) cosmic_python-tornado: not-affected (3.2.2-1) disco_python-tornado: not-affected (3.2.2-1) devel_python-tornado: not-affected (3.2.2-1)