Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-hj3f-6gcp-jg8j: Open redirect in Tornado

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

ghsa
#vulnerability#web#git#auth

Open redirect in Tornado

High severity GitHub Reviewed Published May 25, 2023 to the GitHub Advisory Database • Updated May 25, 2023

Related news

Ubuntu Security Notice USN-6159-1

Ubuntu Security Notice 6159-1 - It was discovered that Tornado incorrectly handled certain redirect. An remote attacker could possibly use this issue to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

CVE-2023-28370: Tornado vulnerable to open redirect

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.