Moderate severityNVD Advisory· Published May 25, 2023· Updated Nov 3, 2025
CVE-2023-28370
CVE-2023-28370
Description
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tornadoPyPI | < 6.3.2 | 6.3.2 |
Affected products
91- ghsa-coords90 versionspkg:pypi/tornadopkg:rpm/almalinux/python3-tornadopkg:rpm/opensuse/prometheus-blackbox_exporter&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/prometheus-blackbox_exporter&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python-tornado&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/python-tornado&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python-tornado&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/python-tornado&distro=openSUSE%20Leap%20Micro%205.4pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/salt&distro=openSUSE%20Leap%20Micro%205.4pkg:rpm/opensuse/spacecmd&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/spacecmd&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/system-user-prometheus&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/system-user-prometheus&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/kiwi-desc-saltboot&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Manager%20Client%20Tools%20for%20SLE%20Micro%205pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Manager%20Proxy%20Module%204.2pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Manager%20Proxy%20Module%204.3pkg:rpm/suse/python-tornado&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python-tornado&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/python-tornado&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Advanced%20Systems%20Management%2012pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP3pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/python-tornado&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/python-tornado&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/python-tornado&distro=SUSE%20Manager%20Proxy%204.2pkg:rpm/suse/python-tornado&distro=SUSE%20Manager%20Server%204.2pkg:rpm/suse/python-tornado&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python-tornado&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-tornado&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python-tornado&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/saltbundlepy-psutil&distro=SUSE:EL-9:Update:Products:SaltBundle:Updatepkg:rpm/suse/salt&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/salt&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP5pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Transactional%20Server%2015%20SP4pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Transactional%20Server%2015%20SP5pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP3pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/salt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/salt&distro=SUSE%20Manager%20Proxy%204.2pkg:rpm/suse/salt&distro=SUSE%20Manager%20Server%204.2pkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/system-user-prometheus&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/system-user-prometheus&distro=SUSE%20Manager%20Client%20Tools%20for%20SLE%20Micro%205pkg:rpm/suse/system-user-prometheus&distro=SUSE%20Manager%20Proxy%20Module%204.2pkg:rpm/suse/system-user-prometheus&distro=SUSE%20Manager%20Proxy%20Module%204.3pkg:rpm/suse/system-user-prometheus&distro=SUSE%20Manager%20Server%20Module%204.2pkg:rpm/suse/system-user-prometheus&distro=SUSE%20Manager%20Server%20Module%204.3pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%2012pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%2015pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%20for%20RHEL,%20Liberty%20and%20Clones%209-CLIENT-TOOLSpkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Client%20Tools%20for%20SLE%20Micro%205pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Proxy%20Module%204.3pkg:rpm/suse/venv-salt-minion&distro=SUSE%20Manager%20Server%20Module%204.3pkg:rpm/suse/venv-salt-minion&distro=SUSE:EL-9:Update:Products:SaltBundle:Update
< 6.3.2+ 89 more
- (no CPE)range: < 6.3.2
- (no CPE)range: < 6.1.0-9.el9
- (no CPE)range: < 0.24.0-150000.1.20.2
- (no CPE)range: < 0.24.0-150000.1.20.2
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 3006.0-150400.8.37.2
- (no CPE)range: < 3006.0-150500.4.12.2
- (no CPE)range: < 3006.0-150400.8.37.2
- (no CPE)range: < 3006.0-150400.8.37.2
- (no CPE)range: < 4.3.22-150000.3.101.1
- (no CPE)range: < 4.3.22-150000.3.101.1
- (no CPE)range: < 1.0.0-150000.10.1
- (no CPE)range: < 1.0.0-150000.10.1
- (no CPE)range: < 0.1.1687520761.cefb248-1.35.2
- (no CPE)range: < 0.24.0-1.20.3
- (no CPE)range: < 0.24.0-150000.1.20.2
- (no CPE)range: < 0.24.0-150000.1.20.2
- (no CPE)range: < 0.24.0-150000.1.20.2
- (no CPE)range: < 0.24.0-150000.1.20.2
- (no CPE)range: < 4.4.3-3.3.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.2.1-17.7.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.2.1-17.7.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.5.3-150000.3.6.1
- (no CPE)range: < 4.4.3-3.3.1
- (no CPE)range: < 4.5.3-3.3.1
- (no CPE)range: < 4.4.3-3.3.1
- (no CPE)range: < 4.5.3-3.3.1
- (no CPE)range: < 5.8.0-1.9.1
- (no CPE)range: < 3006.0-150200.101.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 3006.0-150100.100.2
- (no CPE)range: < 3006.0-150200.101.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 3006.0-150400.8.37.2
- (no CPE)range: < 3006.0-150400.8.37.2
- (no CPE)range: < 3006.0-150400.8.37.2
- (no CPE)range: < 3006.0-150500.4.12.2
- (no CPE)range: < 3006.0-150400.8.37.2
- (no CPE)range: < 3006.0-150500.4.12.2
- (no CPE)range: < 3006.0-150400.8.37.2
- (no CPE)range: < 3006.0-150500.4.12.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 3006.0-150100.100.2
- (no CPE)range: < 3006.0-150200.101.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 3006.0-150100.100.2
- (no CPE)range: < 3006.0-150200.101.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 3006.0-150300.53.53.2
- (no CPE)range: < 4.3.22-38.124.3
- (no CPE)range: < 4.3.22-150000.3.101.1
- (no CPE)range: < 1.0.0-150000.10.1
- (no CPE)range: < 1.0.0-150000.10.1
- (no CPE)range: < 1.0.0-150000.10.1
- (no CPE)range: < 1.0.0-150000.10.1
- (no CPE)range: < 1.0.0-150000.10.1
- (no CPE)range: < 1.0.0-150000.10.1
- (no CPE)range: < 3006.0-3.33.2
- (no CPE)range: < 3006.0-150000.3.35.1
- (no CPE)range: < 3006.0-1.19.2
- (no CPE)range: < 3006.0-150000.3.35.1
- (no CPE)range: < 3006.0-150000.3.35.1
- (no CPE)range: < 3006.0-150000.3.35.1
- (no CPE)range: < 3006.0-1.19.2
- Range: versions 6.3.1 and earlier
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-hj3f-6gcp-jg8jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-28370ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2023-75.yamlghsaWEB
- github.com/tornadoweb/tornado/commit/32ad07c54e607839273b4e1819c347f5c8976b2fghsaWEB
- github.com/tornadoweb/tornado/releases/tag/v6.3.2ghsaWEB
- jvn.jp/en/jp/JVN45127776ghsaWEB
- lists.debian.org/debian-lts-announce/2025/01/msg00000.htmlghsaWEB
- jvn.jp/en/jp/JVN45127776/mitre
News mentions
0No linked articles in our index yet.