Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p8q5-cvwx-wvwp

Опубликовано: 03 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 3.7

Описание

Flask-AppBuilder Observable Response Discrepancy

Impact

User enumeration in database authentication in Flask-AppBuilder <= 4.5.3 and werkzeug >= 3.0.0. Allows for a non authenticated user to enumerate existing usernames by timing the response time from the server when brute forcing requests to login.

Patches

Upgrade to flask-appbuilder>=4.5.3

Workarounds

Downgrade werkzeug to <3.0.0

References

Are there any links users can visit to find out more?

Пакеты

Наименование

flask-appbuilder

pip
Затронутые версииВерсия исправления

< 4.5.3

4.5.3

EPSS

Процентиль: 47%
0.00237
Низкий

3.7 Low

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 3.7
nvd
11 месяцев назад

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.

CVSS3: 3.7
debian
11 месяцев назад

Flask-AppBuilder is an application development framework. Prior to 4.5 ...

EPSS

Процентиль: 47%
0.00237
Низкий

3.7 Low

CVSS3

Дефекты

CWE-204