CVE-2020-28724: Medium severity werkzeug vulnerability
Published Nov 18, 2020
·Updated
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
Affected Software
2 affected componentsFixes available
pip/werkzeug<0.11.6
0.11.6
palletsprojects Werkzeug<0.11.6
Remediation
Patch Available
Event History
Nov 18, 2020
CVE Published
via MITRE·02:26 PM
Data Sourced
via MITRE·02:26 PM
Description
Apr 20, 2021
Advisory Published
04:30 PM
Frequently Asked Questions
1
What is CVE-2020-28724?
CVE-2020-28724 is an open redirect vulnerability in Werkzeug before version 0.11.6 that can be exploited via a double slash in the URL.
2
How severe is CVE-2020-28724?
CVE-2020-28724 has a severity score of 6.1, indicating a medium level of severity.
3
Which software versions are affected by CVE-2020-28724?
Werkzeug versions up to and excluding 0.11.6 are affected by CVE-2020-28724.
4
How can I fix CVE-2020-28724?
To fix CVE-2020-28724, update Werkzeug to version 0.11.6 or newer.
5
Where can I find more information about CVE-2020-28724?
You can find more information about CVE-2020-28724 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-28724), [GitHub Issue 1639](https://github.com/pallets/flask/issues/1639), [GitHub Issue 822](https://github.com/pallets/werkzeug/issues/822).