CVE-2023-28370: Tornadoweb Tornado

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.

Affected products

Published 2023-05-25. Last modified 2026-06-17.