VDB

PYSEC-2023-75

PYSEC-2023-75 PUBLISHED

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

Affected Products

VendorProductVersions
PyPItornado0, 1.2, 1.2.1

Timeline

  • May 25, 2023 CVE Published
  • Nov 8, 2023 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›