Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-28370

Опубликовано: 25 мая 2023
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

A vulnerability was found in the python-tornado library. This flaw causes an open redirect vulnerability that allows a remote, unauthenticated attacker to redirect a user to an arbitrary website and conduct a phishing attack by having the user access a specially crafted URL.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7python-tornadoOut of support scope
Red Hat Enterprise Linux 8pcsNot affected
Red Hat Enterprise Linux 9pcsNot affected
Red Hat OpenShift Container Platform 4python-tornadoNot affected
Red Hat Enterprise Linux 9python-tornadoFixedRHSA-2023:652307.11.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2210199python-tornado: open redirect vulnerability in StaticFileHandler under certain configurations

EPSS

Процентиль: 62%
0.0043
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 2 лет назад

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

CVSS3: 6.1
nvd
около 2 лет назад

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

CVSS3: 6.1
msrc
3 месяца назад

Описание отсутствует

CVSS3: 6.1
debian
около 2 лет назад

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allo ...

suse-cvrf
почти 2 года назад

Security update for salt

EPSS

Процентиль: 62%
0.0043
Низкий

7.4 High

CVSS3