Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.
History

Sat, 07 Dec 2024 02:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_eus:9.4

Thu, 05 Dec 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_eus:9.2
Vendors & Products Redhat rhel Eus

Mon, 02 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

Tue, 26 Nov 2024 03:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 25 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Tornadoweb
Tornadoweb tornado
CPEs cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
Vendors & Products Tornadoweb
Tornadoweb tornado
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 22 Nov 2024 16:00:00 +0000

Type Values Removed Values Added
Description Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.
Title Tornado has HTTP cookie parsing DoS vulnerability
Weaknesses CWE-400
CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-22T15:43:38.572Z

Updated: 2024-11-25T17:55:43.782Z

Reserved: 2024-11-15T17:11:13.441Z

Link: CVE-2024-52804

cve-icon Vulnrichment

Updated: 2024-11-25T17:55:37.644Z

cve-icon NVD

Status : Received

Published: 2024-11-22T16:15:34.417

Modified: 2024-11-22T16:15:34.417

Link: CVE-2024-52804

cve-icon Redhat

Severity : Important

Publid Date: 2024-11-22T15:43:38Z

Links: CVE-2024-52804 - Bugzilla