-
Notifications
You must be signed in to change notification settings - Fork 6
Description
Vulnerable Package issue exists @ Python-tornado-4.5.1 in branch main
Open Redirect vulnerability in tornado versions prior to 6.3.2, allows an unauthenticated remote attacker to redirect a user to an arbitrary website and conduct a phishing attack by having the user access a specially crafted URL.
Namespace: pedrompflopes
Repository: small-project
Repository Url: https://github.com/pedrompflopes/small-project
CxAST-Project: pedrompflopes/small-project
CxAST platform scan: c8ffe959-aafe-486d-a7e7-1ba92f6aee49
Branch: main
Application: small-project
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
CWE: CWE-601
Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE
Remediation Upgrade Recommendation: 6.3.2
References
Advisory
Pull request
Commit
Release Note