Логотип exploitDog
bind:CVE-2021-41265
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-41265

Количество 3

Количество 3

nvd логотип

CVE-2021-41265

около 4 лет назад

Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2021-41265

около 4 лет назад

Flask-AppBuilder is a development framework built on top of Flask. Ver ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-m3rf-7m4w-r66q

около 4 лет назад

Improper Authentication in Flask-AppBuilder

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-41265

Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.

CVSS3: 8.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-41265

Flask-AppBuilder is a development framework built on top of Flask. Ver ...

CVSS3: 8.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-m3rf-7m4w-r66q

Improper Authentication in Flask-AppBuilder

CVSS3: 8.1
0%
Низкий
около 4 лет назад

Уязвимостей на страницу