Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wv5-4vpf-pj6m

Опубликовано: 19 июл. 2019
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Pallets Project Flask is vulnerable to Denial of Service via Unexpected memory usage

The Pallets Project Flask before 1.0 is affected by unexpected memory usage. The impact is denial of service. The attack vector is crafted encoded JSON data. The fixed version is 1. NOTE this may overlap CVE-2018-1000656.

Пакеты

Наименование

Flask

pip
Затронутые версииВерсия исправления

< 1.0

1.0

EPSS

Процентиль: 60%
0.00399
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.

CVSS3: 7.5
redhat
почти 8 лет назад

The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.

CVSS3: 7.5
nvd
больше 6 лет назад

The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.

CVSS3: 7.5
debian
больше 6 лет назад

The Pallets Project Flask before 1.0 is affected by: unexpected memory ...

suse-cvrf
почти 3 года назад

Security update for python-Flask

EPSS

Процентиль: 60%
0.00399
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400