Описание
flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a server side session. In versions prior to 1.2.1, he captcha.validate() function would return None if passed no value (e.g. by submitting an having an empty form). If implementing users were checking the return value to be False, the captcha verification check could be bypassed. Version 1.2.1 fixes the issue. Users can workaround the issue by not explicitly checking that the value is False. Checking the return value less explicitly should still work.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.1 (исключая)
cpe:2.3:a:flask-session-captcha_project:flask-session-captcha:*:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.0025
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-253
CWE-754
Связанные уязвимости
CVSS3: 5.3
github
почти 4 года назад
Potential Captcha Validate Bypass in flask-session-captcha
EPSS
Процентиль: 48%
0.0025
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-253
CWE-754