[Git][security-tracker-team/security-tracker][master] "new" python-tornado issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 16 11:26:14 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b2d78ebe by Moritz Muehlenhoff at 2026-09-16T12:25:48+02:00
"new" python-tornado issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1074,9 +1074,11 @@ CVE-2025-13166 (The SMS OTP flow fails to adequately handle error messages, allo
CVE-2024-58385 (Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability ...)
TODO: check
CVE-2024-58384 (Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAs ...)
- TODO: check
+ - python-tornado 6.4.1-1
+ NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-w235-7p84-xx57
CVE-2024-14029 (Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked head ...)
- TODO: check
+ - python-tornado 6.4.1-1
+ NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-753j-mpmx-qq6g
CVE-2023-54398 (Yonyou U8 Cloud contains an unauthenticated Java deserialization vulne ...)
TODO: check
CVE-2023-54397 (Tornado before 6.3.3 contains an HTTP request smuggling vulnerability ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2d78ebed0e20e5a3321ff3d35c9642906abb9c8
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2d78ebed0e20e5a3321ff3d35c9642906abb9c8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/c907e35c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list