-
Notifications
You must be signed in to change notification settings - Fork 5.5k
Closed
Description
We believe that tornado 2.2.1 in EPEL6 is vulnerable to the XSRF CVE - bug is filed here:
https://bugzilla.redhat.com/show_bug.cgi?id=1222820
I made a quick attempt to backport the 3.2.2 fix (attached to bug report), but it does not look good. I'm hoping for a little help/advice from upstream. Perhaps updating to a somewhat newer tornado in EPEL6 first would be good, but we can't break API. Any suggestions?
Metadata
Metadata
Assignees
Labels
No labels