tornado is vulnerable to Cross-Site Scripting (XSS)
54
Medium Risk
The reason argument (used by both RequestHandler.set_status and tornado.web.HTTPError) is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes).
You are affected if you are using a version that falls within the vulnerable range and if untrusted data is passed to the reason argument.
tornado is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.0 - 6.5.2.
Upgrade the tornado library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant