Description
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
Remediation
References
Related Vulnerabilities
WordPress Plugin Featured Comments Cross-Site Request Forgery (1.2.4)
Play Framework Out-of-bounds Write Vulnerability (CVE-2020-27196)
Sqlite Out-of-bounds Read Vulnerability (CVE-2019-9936)
Oracle JRE CVE-2012-3216 Vulnerability (CVE-2012-3216)
WordPress Plugin AccessPress Social Icons Cross-Site Scripting (1.6.6)