rpm package
suse/python-backports.ssl_match_hostname&distro=SUSE Linux Enterprise Workstation Extension 12
pkg:rpm/suse/python-backports.ssl_match_hostname&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2014-9720 | — | < 3.4.0.2-15.1 | 3.4.0.2-15.1 | Jan 24, 2020 | Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests. |
- CVE-2014-9720Jan 24, 2020affected < 3.4.0.2-15.1fixed 3.4.0.2-15.1
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.