NA

CVE-2020-28476

Published: 18/01/2021 Updated: 07/11/2023

Vulnerability Summary

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-23336. Reason: This candidate is a reservation duplicate of CVE-2021-23336. Notes: All CVE users should reference CVE-2021-23336 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

Vulnerability Trend

Vendor Advisories

All versions of the package python-tornado are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server This can result i ...