PT-2021-19942 · Pypi · Flask-Appbuilder

Dpgaspar

·

Published

2021-09-08

·

Updated

2021-09-15

·

CVE-2021-32805

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Flask-AppBuilder versions prior to 3.2.2
Description The issue is an open redirect vulnerability that occurs when using Flask-AppBuilder OAuth. An attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-AppBuilder, which can redirect a user to a malicious site.
Recommendations To resolve this issue, upgrade to Flask-AppBuilder 3.2.2 or above. If upgrading is infeasible, filter HTTP traffic containing ?next={next-site} where the next-site domain is different from the application you are protecting as a workaround.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32805
GHSA-624F-CQVR-3QW4
PYSEC-2021-359

Affected Products

Flask-Appbuilder