Tornado web application can store a user's data in a cookie. For protection against cookie data tampering, Tornado signs the cookie value with a secret key. It's very important that an attacker doesn't know the value of this secret key. Your application is using a weak/known secret key and Acunetix managed to guess this key.


Change the value of cookie_secret to a long random string. The impact varies depending on how the cookie is used.


Related Vulnerabilities