HTTP Request Smuggling in Tornado Web Framework by Tornado
CVE-2024-14029
9CRITICAL
What is CVE-2024-14029?
The Tornado Web Framework versions prior to 6.4.1 have a vulnerability where duplicate Transfer-Encoding: chunked headers are improperly handled. This mismanagement results in the framework disregarding the existence of a message body and misinterpreting the chunked body as an additional request. Attackers can exploit this flaw, particularly when Tornado operates behind proxies, to execute an HTTP request smuggling attack. This exploitation could lead to various security issues, including unauthorized access control bypass, cache poisoning risks, and connection desynchronization, threatening the overall integrity and security of the application.
Affected Version(s)
tornado 0 < 6.4.1
tornado 6.4.1
