CVE-2020-28724Open Redirect in Werkzeug

CWE-601Open Redirect9 documents7 sources
Severity
6.1MEDIUMNVD
OSV7.5
EPSS
0.9%
top 23.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 18
Latest updateApr 20

Description

Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Patches

🔴Vulnerability Details

5
OSV
Open Redirect in werkzeug2021-04-20
GHSA
Open Redirect in werkzeug2021-04-20
OSV
python-werkzeug vulnerabilities2020-12-01
CVEList
CVE-2020-28724: Open redirect vulnerability in werkzeug before 02020-11-18
OSV
CVE-2020-28724: Open redirect vulnerability in werkzeug before 02020-11-18

📋Vendor Advisories

3
Ubuntu
Werkzeug vulnerabilities2020-12-01
Debian
CVE-2020-28724: python-werkzeug - Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the ...2020
Red Hat
python-werkzeug: open redirect via double slash in the URL2015-12-06
CVE-2020-28724 — Open Redirect in Werkzeug | cvebase