Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

1 – 10 of 13 results


CVE-2024-6221

Medium priority
Needs evaluation

A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network...

1 affected packages

python-flask-cors

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
python-flask-cors Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-1681

Medium priority
Needs evaluation

corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in...

1 affected packages

python-flask-cors

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
python-flask-cors Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2023-34110

Medium priority
Ignored

Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a special character on the add, edit User...

1 affected packages

flask-appbuilder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
flask-appbuilder Not in release Not in release Ignored Ignored
Show less packages

CVE-2023-30861

Medium priority
Fixed

Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the...

1 affected packages

flask

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
flask Fixed Fixed Not affected Not affected
Show less packages

CVE-2023-29005

Medium priority
Ignored

Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED...

1 affected packages

flask-appbuilder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
flask-appbuilder Not in release Not in release Not in release Ignored
Show less packages

CVE-2021-23385

Medium priority

Some fixes available 3 of 8

This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing...

1 affected packages

flask-security

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
flask-security Not affected Fixed Fixed Fixed Not in release
Show less packages

CVE-2022-31177

Low priority
Ignored

Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These...

1 affected packages

flask-appbuilder

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
flask-appbuilder Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-32618

Low priority
Ignored

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions...

1 affected packages

flask-security

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
flask-security Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2021-33026

Medium priority
Ignored

** DISPUTED ** The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g.,...

1 affected packages

flask-caching

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
flask-caching Not affected Not affected Not affected Not in release Ignored
Show less packages

CVE-2021-21241

Medium priority
Ignored

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security....

1 affected packages

flask-security

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
flask-security Not affected Not affected Not affected Not affected Not in release
Show less packages