CVE-2024-52804
Last modified
CVE-2024-52804 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tornadoweb | Tornado | < 6.4.2 |
References
- https://github.com/advisories/GHSA-7pwv-g7hj-39prNot Applicable
- https://github.com/tornadoweb/tornado/security/advisories/GHSA-8w49-h785-mj3cThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-52804?
How severe is CVE-2024-52804?
How do I fix CVE-2024-52804?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-52799Argo Workflows Chart is used to set up argo and its needed d…8.2
- CVE-2024-5280The wp-affiliate-platform WordPress plugin before 6.5.1 does…4.7
- CVE-2024-52800veraPDF is an open source PDF/A validation library. Executin…2.3
- CVE-2024-52801sftpgo is a full-featured and highly configurable event-driv…5.3
- CVE-2024-52802RIOT is an operating system for internet of things (IoT) dev…7.5
- CVE-2024-52803LLama Factory enables fine-tuning of large language models. …9.8
- CVE-2024-52805Synapse is an open-source Matrix homeserver. In Synapse befo…7.5
- CVE-2024-52806SimpleSAMLphp SAML2 library is a PHP library for SAML2 relat…8.3
- CVE-2024-52807The HL7 FHIR IG publisher is a tool to take a set of inputs …8.6
- CVE-2024-52809vue-i18n is an internationalization plugin for Vue.js. In a…5.3
- CVE-2024-5281The wp-affiliate-platform WordPress plugin before 6.5.1 does…6.1
- CVE-2024-52810@intlify/shared is a shared library for the intlify project.…6.9
Are you affected by CVE-2024-52804?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
