id: PYSEC-2023-75 details: Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL. affected: - package: name: tornado ecosystem: PyPI purl: pkg:pypi/tornado ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 6.3.2 versions: - "0.2" - "1.0" - "1.1" - 1.1.1 - "1.2" - 1.2.1 - "2.0" - "2.1" - 2.1.1 - "2.2" - 2.2.1 - "2.3" - "2.4" - 2.4.1 - "3.0" - 3.0.1 - 3.0.2 - "3.1" - 3.1.1 - "3.2" - 3.2.1 - 3.2.2 - "4.0" - 4.0.1 - 4.0.2 - "4.1" - 4.1b2 - "4.2" - 4.2.1 - 4.2b1 - "4.3" - 4.3b1 - 4.3b2 - "4.4" - 4.4.1 - 4.4.2 - 4.4.3 - 4.4b1 - "4.5" - 4.5.1 - 4.5.2 - 4.5.3 - 4.5b1 - 4.5b2 - "5.0" - 5.0.1 - 5.0.2 - 5.0a1 - 5.0b1 - "5.1" - 5.1.1 - 5.1b1 - "6.0" - 6.0.1 - 6.0.2 - 6.0.3 - 6.0.4 - 6.0a1 - 6.0b1 - "6.1" - 6.1b1 - 6.1b2 - "6.2" - 6.2b1 - 6.2b2 - "6.3" - 6.3.1 - 6.3b1 references: - type: WEB url: https://jvn.jp/en/jp/JVN45127776/ - type: WEB url: https://github.com/tornadoweb/tornado/releases/tag/v6.3.2 - type: ADVISORY url: https://github.com/advisories/GHSA-hj3f-6gcp-jg8j aliases: - CVE-2023-28370 - GHSA-hj3f-6gcp-jg8j modified: "2023-06-05T01:13:01.694311Z" published: "2023-05-25T10:15:00Z"