PT-2018-9508 · Pallets+2 · Flask+2
David Lord
+1
·
Publicado
2018-08-20
·
Atualizado
2020-06-09
·
CVE-2018-1000656
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flask versions prior to 0.12.3
Description
The issue is related to improper input validation, which can result in a large amount of memory usage, possibly leading to denial of service. This can be exploited when an attacker provides JSON data in incorrect encoding.
Recommendations
For versions prior to 0.12.3, update to version 0.12.3 to resolve the issue. As a temporary workaround, consider restricting the handling of JSON data with incorrect encoding to minimize the risk of exploitation.
Correção
DoS
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Flask
Suse
Ubuntu