Loading
Generated remediation guidance and an executive summary. No account required.
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
Cite this page
CVE-2023-28370. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2023-28370
Use CWE-601, Tornadoweb vendor hub and Tornado product page to widen CVE-2023-28370 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-31958, CVE-2025-67726 and CVE-2025-67725 for nearby disclosures in the same product family.