CVE-2023-28370: Tornadoweb Tornado
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
Affected products
- Tornadoweb Tornado: before 6.3.2 (fixed in 6.3.2)
Published 2023-05-25. Last modified 2026-06-17.