MEDIUM 6.1 PyPI
Open Redirect in werkzeug
GHSA-3p3h-qghp-hvh2 · CVE-2020-28724 · PYSEC-2020-157
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-28724
- WEB https://github.com/pallets/flask/issues/1639
- WEB https://github.com/pallets/werkzeug/issues/822
- WEB https://github.com/pallets/werkzeug/pull/890/files
- PACKAGE https://github.com/pallets/werkzeug
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/werkzeug/PYSEC-2020-157.yaml
Ready to move
Start Securing
Free, no credit card | First findings in minutes