Junglewise Threat Intelligence
CVE-2012-2374: PYSEC-2012-5 - CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject
CVE-2012-2374 · Severity: low · CVSS 3.1 · Published 2012-05-23
Technologies: tornado (PyPI). Vendors: PyPI.
Executive brief
CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.