Medium severity6.1NVD Advisory· Published Nov 18, 2020· Updated Jun 17, 2026
CVE-2020-28724
CVE-2020-28724
Description
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
werkzeugPyPI | < 0.11.6 | 0.11.6 |
Affected products
3- werkzeug/werkzeugdescription
Patches
Vulnerability mechanics
References
6- github.com/pallets/werkzeug/pull/890/filesnvdPatchThird Party AdvisoryWEB
- github.com/pallets/flask/issues/1639nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-3p3h-qghp-hvh2ghsaADVISORY
- github.com/pallets/werkzeug/issues/822nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-28724ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/werkzeug/PYSEC-2020-157.yamlghsaWEB
News mentions
0No linked articles in our index yet.