CVE-2023-28370
25.05.2023, 10:15
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
Vendor | Product | Version |
---|---|---|
tornadoweb | tornado | 𝑥 < 6.3.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python-tornado |
| ||||||||||||||||||||
salt |
|
Common Weakness Enumeration