Количество 6
Количество 6
CVE-2024-6866
corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive, but the regex matching treats them as case-insensitive. This misconfiguration can lead to significant security vulnerabilities, allowing unauthorized origins to access paths meant to be restricted, resulting in data exposure and potential data leaks.
CVE-2024-6866
corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive, but the regex matching treats them as case-insensitive. This misconfiguration can lead to significant security vulnerabilities, allowing unauthorized origins to access paths meant to be restricted, resulting in data exposure and potential data leaks.
CVE-2024-6866
corydolphin/flask-cors version 4.01 contains a vulnerability where the ...
GHSA-43qf-4rqw-9q2g
Flask-CORS vulnerable to Improper Handling of Case Sensitivity
BDU:2024-07532
Уязвимость функции try_match хранилища программных продуктов языка Python PyPi, позволяющая нарушителю оказать влияние на конфиденциальность защищаемой информации
ROS-20250912-09
Множественные уязвимости python3-flask-cors
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-6866 corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive, but the regex matching treats them as case-insensitive. This misconfiguration can lead to significant security vulnerabilities, allowing unauthorized origins to access paths meant to be restricted, resulting in data exposure and potential data leaks. | CVSS3: 7.5 | 0% Низкий | 10 месяцев назад | |
CVE-2024-6866 corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive, but the regex matching treats them as case-insensitive. This misconfiguration can lead to significant security vulnerabilities, allowing unauthorized origins to access paths meant to be restricted, resulting in data exposure and potential data leaks. | CVSS3: 7.5 | 0% Низкий | 10 месяцев назад | |
CVE-2024-6866 corydolphin/flask-cors version 4.01 contains a vulnerability where the ... | CVSS3: 7.5 | 0% Низкий | 10 месяцев назад | |
GHSA-43qf-4rqw-9q2g Flask-CORS vulnerable to Improper Handling of Case Sensitivity | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
BDU:2024-07532 Уязвимость функции try_match хранилища программных продуктов языка Python PyPi, позволяющая нарушителю оказать влияние на конфиденциальность защищаемой информации | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
ROS-20250912-09 Множественные уязвимости python3-flask-cors | CVSS3: 6.5 | 4 месяца назад |
Уязвимостей на страницу