PT-2021-19942 · Pypi · Flask-Appbuilder
Dpgaspar
·
Published
2021-09-08
·
Updated
2021-09-15
·
CVE-2021-32805
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Flask-AppBuilder versions prior to 3.2.2
Description
The issue is an open redirect vulnerability that occurs when using Flask-AppBuilder OAuth. An attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-AppBuilder, which can redirect a user to a malicious site.
Recommendations
To resolve this issue, upgrade to Flask-AppBuilder 3.2.2 or above.
If upgrading is infeasible, filter HTTP traffic containing
?next={next-site} where the next-site domain is different from the application you are protecting as a workaround.Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flask-Appbuilder