PT-2018-9508 · Pallets+2 · Flask+2
David Lord
+1
·
Published
2018-08-20
·
Updated
2020-06-09
·
CVE-2018-1000656
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Flask versions prior to 0.12.3
Description
The issue is related to improper input validation, which can result in a large amount of memory usage, possibly leading to denial of service. This can be exploited when an attacker provides JSON data in incorrect encoding.
Recommendations
For versions prior to 0.12.3, update to version 0.12.3 to resolve the issue. As a temporary workaround, consider restricting the handling of JSON data with incorrect encoding to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flask
Suse
Ubuntu