Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3rf-7m4w-r66q

Опубликовано: 09 дек. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

Improper Authentication in Flask-AppBuilder

Impact

Improper authentication on the REST API. Allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. Only affects non database authentication types, and new REST API endpoints.

Patches

Upgrade to Flask-AppBuilder 3.3.4

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

Flask-AppBuilder

pip
Затронутые версииВерсия исправления

< 3.3.4

3.3.4

EPSS

Процентиль: 55%
0.00328
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.1
nvd
около 4 лет назад

Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.

CVSS3: 8.1
debian
около 4 лет назад

Flask-AppBuilder is a development framework built on top of Flask. Ver ...

EPSS

Процентиль: 55%
0.00328
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-287