Skip to content

CVE-2023-28370 @ Python-tornado-4.5.1 #28

@cx-pedro-lopes

Description

@cx-pedro-lopes

Vulnerable Package issue exists @ Python-tornado-4.5.1 in branch main

Open Redirect vulnerability in tornado versions prior to 6.3.2, allows an unauthenticated remote attacker to redirect a user to an arbitrary website and conduct a phishing attack by having the user access a specially crafted URL.

Namespace: pedrompflopes
Repository: small-project
Repository Url: https://github.com/pedrompflopes/small-project
CxAST-Project: pedrompflopes/small-project
CxAST platform scan: c8ffe959-aafe-486d-a7e7-1ba92f6aee49
Branch: main
Application: small-project
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
CWE: CWE-601


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
Remediation Upgrade Recommendation: 6.3.2


References
Advisory
Pull request
Commit
Release Note

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions