Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-28370

Опубликовано: 25 мая 2023
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
Версия до 6.3.2 (исключая)

EPSS

Процентиль: 61%
0.00418
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601
CWE-601

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 2 лет назад

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

CVSS3: 7.4
redhat
больше 2 лет назад

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

CVSS3: 6.1
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 6.1
debian
больше 2 лет назад

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allo ...

suse-cvrf
около 2 лет назад

Security update for salt

EPSS

Процентиль: 61%
0.00418
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601
CWE-601