CVE-2023-28370
25.05.2023, 10:15
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
| Vendor | Product | Version |
|---|---|---|
| tornadoweb | tornado | 𝑥 < 6.3.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python-tornado |
| ||||||||||||||||||||
| salt |
|
Common Weakness Enumeration