Количество 7
Количество 7
CVE-2020-25032
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVE-2020-25032
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVE-2020-25032
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVE-2020-25032
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) ...
openSUSE-SU-2020:1393-1
Security update for python-Flask-Cors
GHSA-xc3p-ff3m-f46v
Flask-Cors Directory Traversal vulnerability
BDU:2021-01702
Уязвимость дополнения для обработки разделения ресурсов между источниками Flask-CORS, связанная с недостатком механизма контроля инициализируемых ресурсов, позволяющая нарушителю получить доступ к конфиденциальным данным
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-25032 An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. | CVSS3: 7.5 | 1% Низкий | больше 5 лет назад | |
CVE-2020-25032 An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. | CVSS3: 7.5 | 1% Низкий | больше 5 лет назад | |
CVE-2020-25032 An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. | CVSS3: 7.5 | 1% Низкий | больше 5 лет назад | |
CVE-2020-25032 An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) ... | CVSS3: 7.5 | 1% Низкий | больше 5 лет назад | |
openSUSE-SU-2020:1393-1 Security update for python-Flask-Cors | 1% Низкий | больше 5 лет назад | ||
GHSA-xc3p-ff3m-f46v Flask-Cors Directory Traversal vulnerability | CVSS3: 7.5 | 1% Низкий | почти 5 лет назад | |
BDU:2021-01702 Уязвимость дополнения для обработки разделения ресурсов между источниками Flask-CORS, связанная с недостатком механизма контроля инициализируемых ресурсов, позволяющая нарушителю получить доступ к конфиденциальным данным | CVSS3: 7.5 | 1% Низкий | больше 5 лет назад |
Уязвимостей на страницу