CRLF Injection Vulnerability in Tornado Web Framework by Tornado
CVE-2024-58384
6.3MEDIUM
What is CVE-2024-58384?
The Tornado Web Framework prior to version 6.4.1 contains a vulnerability that permits CRLF injection through the CurlAsyncHTTPClient component. This flaw occurs when the framework fails to properly sanitize carriage return and line feed characters in HTTP request headers. As a result, malicious attackers can exploit this vulnerability to inject custom headers or forge completely new HTTP requests, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
tornado 0 < 6.4.1
tornado 6.4.1
