Junglewise Threat Intelligence

CVE-2012-2374: PYSEC-2012-5 - CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject

CVE-2012-2374 · Severity: low · CVSS 3.1 · Published 2012-05-23

Technologies: tornado (PyPI). Vendors: PyPI.

Executive brief

CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.

Affected products

  • PyPI tornado

Related threats