CVE-2020-28724
Ubuntu Security Notice USN-4655-1
Severity Score
6.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
Una vulnerabilidad de redireccionamiento abierto en werkzeug versiones anteriores a 0.11.6 por medio de una barra doble en la URL
It was discovered that Werkzeug has insufficient debugger PIN randomness. An attacker could use this issue to access sensitive information. This issue only affected Ubuntu 18.04 LTS. It was discovered that Werkzeug incorrectly handled certain URLs. An attacker could possibly use this issue to cause phishing attacks. This issue only affected Ubuntu 16.04 LTS.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2020-11-16 CVE Reserved
- 2020-11-18 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/pallets/werkzeug/issues/822 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://github.com/pallets/flask/issues/1639 | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://github.com/pallets/werkzeug/pull/890/files | 2020-12-01 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Palletsprojects Search vendor "Palletsprojects" | Werkzeug Search vendor "Palletsprojects" for product "Werkzeug" | < 0.11.6 Search vendor "Palletsprojects" for product "Werkzeug" and version " < 0.11.6" | - |
Affected
|