Логотип exploitDog
bind:CVE-2024-25128
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-25128

Количество 4

Количество 4

ubuntu логотип

CVE-2024-25128

почти 2 года назад

Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2024-25128

почти 2 года назад

Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2024-25128

почти 2 года назад

Flask-AppBuilder is an application development framework, built on top ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-j2pw-vp55-fqqj

почти 2 года назад

Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-25128

Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.

CVSS3: 9.1
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-25128

Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.

CVSS3: 9.1
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-25128

Flask-AppBuilder is an application development framework, built on top ...

CVSS3: 9.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-j2pw-vp55-fqqj

Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID

CVSS3: 9.1
1%
Низкий
почти 2 года назад

Уязвимостей на страницу