Skip to content

XSRF CVE in tornado 2.2.1 #1447

@opoplawski

Description

@opoplawski

We believe that tornado 2.2.1 in EPEL6 is vulnerable to the XSRF CVE - bug is filed here:

https://bugzilla.redhat.com/show_bug.cgi?id=1222820

I made a quick attempt to backport the 3.2.2 fix (attached to bug report), but it does not look good. I'm hoping for a little help/advice from upstream. Perhaps updating to a somewhat newer tornado in EPEL6 first would be good, but we can't break API. Any suggestions?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions