Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2ccw-7px8-vmpf

Опубликовано: 25 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Open Redirect in Flask-AppBuilder

Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 3.4.5 contain an open redirect vulnerability when using the database authentication login page. There are no known workarounds. Users are recommended to upgrade to version 3.4.5 or later.

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

Flask-AppBuilder

pip
Затронутые версииВерсия исправления

< 3.4.5

3.4.5

EPSS

Процентиль: 57%
0.00347
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
nvd
почти 4 года назад

Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are currently no known workarounds.

CVSS3: 6.1
debian
почти 4 года назад

Flask-AppBuilder is an application development framework, built on top ...

EPSS

Процентиль: 57%
0.00347
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601