Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2024-45314

около 2 лет назад

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for `/login` per the directions provided in the GitHub Security Advisory.

CVSS3: 3.6
EPSS: Низкий
debian логотип

CVE-2024-45314

около 2 лет назад

Flask-AppBuilder is an application development framework. Prior to ver ...

CVSS3: 3.6
EPSS: Низкий
github логотип

GHSA-fw5r-6m3x-rh7p

около 2 лет назад

Flask-AppBuilder's login form allows browser to cache sensitive fields

CVSS3: 3.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-45314

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for `/login` per the directions provided in the GitHub Security Advisory.

CVSS3: 3.6
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-45314

Flask-AppBuilder is an application development framework. Prior to ver ...

CVSS3: 3.6
0%
Низкий
около 2 лет назад
github логотип
GHSA-fw5r-6m3x-rh7p

Flask-AppBuilder's login form allows browser to cache sensitive fields

CVSS3: 3.6
0%
Низкий
около 2 лет назад

Уязвимостей на страницу