Search CVE reports
1 – 10 of 13 results
CVE-2024-6221
Medium priorityA vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network...
1 affected packages
python-flask-cors
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-flask-cors | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
CVE-2024-1681
Medium prioritycorydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in...
1 affected packages
python-flask-cors
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
python-flask-cors | Needs evaluation | Needs evaluation | Needs evaluation | — | — |
CVE-2023-34110
Medium priorityFlask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a special character on the add, edit User...
1 affected packages
flask-appbuilder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
flask-appbuilder | — | Not in release | Not in release | Ignored | Ignored |
CVE-2023-30861
Medium priorityFlask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the...
1 affected packages
flask
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
flask | — | Fixed | Fixed | Not affected | Not affected |
CVE-2023-29005
Medium priorityFlask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED...
1 affected packages
flask-appbuilder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
flask-appbuilder | — | Not in release | Not in release | Not in release | Ignored |
CVE-2021-23385
Medium prioritySome fixes available 3 of 8
This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing...
1 affected packages
flask-security
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
flask-security | Not affected | Fixed | Fixed | Fixed | Not in release |
CVE-2022-31177
Low priorityFlask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These...
1 affected packages
flask-appbuilder
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
flask-appbuilder | — | Not in release | Not in release | Not in release | Not in release |
CVE-2021-32618
Low priorityThe Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions...
1 affected packages
flask-security
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
flask-security | Ignored | Ignored | Ignored | Ignored | Ignored |
CVE-2021-33026
Medium priority** DISPUTED ** The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g.,...
1 affected packages
flask-caching
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
flask-caching | Not affected | Not affected | Not affected | Not in release | Ignored |
CVE-2021-21241
Medium priorityThe Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security....
1 affected packages
flask-security
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
flask-security | Not affected | Not affected | Not affected | Not affected | Not in release |