Junglewise Threat Intelligence
CVE-2023-28370: PYSEC-2023-75 - Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrar
CVE-2023-28370 · Severity: low · CVSS 3.1 · Published 2023-05-25
Technologies: tornado (PyPI). Vendors: PyPI.
Executive brief
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.