Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL. References: https://github.com/pallets/werkzeug/issues/822 https://github.com/pallets/flask/issues/1639 Upstream patch: https://github.com/pallets/werkzeug/pull/890
Created python-werkzeug tracking bugs for this issue: Affects: epel-6 [bug 1899268]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2020-28724