Logo
vulnerabilityCVE-2023-28370
Name
CVE-2023-28370
Source
NVD ( link)Debian ( link)
Description
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-tornado
Patched

Vulnerability Ratings#


6.1
CVSSv31
6.1
CVSSv31
NaN
other

Resolved with patches#


python3-tornado (yocto:kirkstone)

#
Title
Author
Resolve
1
web: Fix an open redirect in StaticFileHandler
Ben Darnell <ben@bendarnell.com>
CVE-2023-28370