PT-2022-16871 · Pypi · Flask-Appbuilder
Dpgaspar
·
Published
2022-03-24
·
Updated
2022-04-05
·
CVE-2022-24776
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Flask-AppBuilder versions prior to 3.4.5
Description
Flask-AppBuilder contains an open redirect vulnerability when using the database authentication login page. This issue is fixed in version 3.4.5. There are currently no known workarounds.
Recommendations
For versions prior to 3.4.5, upgrade to version 3.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the database authentication login page until the upgrade is applied.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flask-Appbuilder