Логотип exploitDog
bind:CVE-2024-45314
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-45314

Количество 3

Количество 3

nvd логотип

CVE-2024-45314

больше 1 года назад

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for `/login` per the directions provided in the GitHub Security Advisory.

CVSS3: 3.6
EPSS: Низкий
debian логотип

CVE-2024-45314

больше 1 года назад

Flask-AppBuilder is an application development framework. Prior to ver ...

CVSS3: 3.6
EPSS: Низкий
github логотип

GHSA-fw5r-6m3x-rh7p

больше 1 года назад

Flask-AppBuilder's login form allows browser to cache sensitive fields

CVSS3: 3.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-45314

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for `/login` per the directions provided in the GitHub Security Advisory.

CVSS3: 3.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-45314

Flask-AppBuilder is an application development framework. Prior to ver ...

CVSS3: 3.6
0%
Низкий
больше 1 года назад
github логотип
GHSA-fw5r-6m3x-rh7p

Flask-AppBuilder's login form allows browser to cache sensitive fields

CVSS3: 3.6
0%
Низкий
больше 1 года назад

Уязвимостей на страницу