PT-2022-16871 · Pypi · Flask-Appbuilder

Dpgaspar

·

Published

2022-03-24

·

Updated

2022-04-05

·

CVE-2022-24776

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Flask-AppBuilder versions prior to 3.4.5
Description Flask-AppBuilder contains an open redirect vulnerability when using the database authentication login page. This issue is fixed in version 3.4.5. There are currently no known workarounds.
Recommendations For versions prior to 3.4.5, upgrade to version 3.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the database authentication login page until the upgrade is applied.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24776
GHSA-2CCW-7PX8-VMPF

Affected Products

Flask-Appbuilder