GHSA-hj3f-6gcp-jg8j

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-hj3f-6gcp-jg8j/GHSA-hj3f-6gcp-jg8j.json
Aliases
  • CVE-2023-28370
Published
2023-05-25T12:30:16Z
Modified
2023-05-26T21:34:14.886146Z
Details

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

References

Affected packages

PyPI / tornado

tornado

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Fixed
6.3.2

Affected versions

0.*

0.2

1.*

1.0
1.1
1.1.1
1.2
1.2.1

2.*

2.0
2.1
2.1.1
2.2
2.2.1
2.3
2.4
2.4.1

3.*

3.0
3.0.1
3.0.2
3.1
3.1.1
3.2
3.2.1
3.2.2

4.*

4.0
4.0.1
4.0.2
4.1
4.1b2
4.2
4.2.1
4.2b1
4.3
4.3b1
4.3b2
4.4
4.4.1
4.4.2
4.4.3
4.4b1
4.5
4.5.1
4.5.2
4.5.3
4.5b1
4.5b2

5.*

5.0
5.0.1
5.0.2
5.0a1
5.0b1
5.1
5.1.1
5.1b1

6.*

6.0
6.0.1
6.0.2
6.0.3
6.0.4
6.0a1
6.0b1
6.1
6.1b1
6.1b2
6.2
6.2b1
6.2b2
6.3
6.3.1
6.3b1

Ecosystem specific

{
    "affected_functions": [
        "tornado.web.StaticFileHandler.validate_absolute_path"
    ]
}