CVE-2024-58384

NameCVE-2024-58384
DescriptionTornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-tornado (PTS)bookworm, bookworm (security)6.2.0-3+deb12u4vulnerable
trixie (security), trixie6.4.2-3+deb13u2fixed
forky, sid6.5.5-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-tornadosource(unstable)6.4.1-1

Notes

https://github.com/tornadoweb/tornado/security/advisories/GHSA-w235-7p84-xx57

Search for package or bug name: Reporting problems