Medium severity6.5NVD Advisory· Published Jan 24, 2020· Updated Jun 17, 2026
CVE-2014-9720
CVE-2014-9720
Description
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tornadoPyPI | < 3.2.2 | 3.2.2 |
Affected products
10- Tornado/Tornadodescription
- ghsa-coords9 versionspkg:pypi/tornadopkg:rpm/suse/python-backports.ssl_match_hostname&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/python-backports.ssl_match_hostname&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/python-backports.ssl_match_hostname&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012pkg:rpm/suse/python-backports.ssl_match_hostname&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Desktop%2012pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP1
< 3.2.2+ 8 more
- (no CPE)range: < 3.2.2
- (no CPE)range: < 3.4.0.2-15.1
- (no CPE)range: < 3.4.0.2-15.1
- (no CPE)range: < 3.4.0.2-15.1
- (no CPE)range: < 3.4.0.2-15.1
- (no CPE)range: < 4.2.1-11.1
- (no CPE)range: < 4.2.1-11.1
- (no CPE)range: < 4.2.1-11.1
- (no CPE)range: < 4.2.1-11.1
Patches
Vulnerability mechanics
References
8- openwall.com/lists/oss-security/2015/05/19/4nvdMailing ListPatchThird Party AdvisoryWEB
- bugzilla.novell.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/tornadoweb/tornado/commit/1c36307463b1e8affae100bf9386948e6c1b2308nvdPatchWEB
- www.tornadoweb.org/en/stable/releases/v3.2.2.htmlnvdRelease NotesVendor AdvisoryWEB
- github.com/advisories/GHSA-8vpw-mgpf-mpvvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-9720ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2020-213.yamlghsaWEB
News mentions
0No linked articles in our index yet.