Product
A path traversal vulnerability in Tornado's StaticFileHandler allows unauthenticated remote attackers to read arbitrary files via symbolic links within the static root directory.