PT-2024-31566 · Pypi · Flask-Appbuilder
Dpgaspar
·
Published
2024-09-04
·
Updated
2024-09-12
·
CVE-2024-45314
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Flask-AppBuilder versions prior to 4.5.1
Description
The auth DB login form default cache directives in Flask-AppBuilder allow browsers to locally store sensitive data. This can be an issue in environments using shared computer resources.
Recommendations
For versions prior to 4.5.1, upgrade to version 4.5.1 to resolve the issue.
If upgrading is not possible, configure your web server to send the specific HTTP headers for "/login", including "Cache-Control": "no-store, no-cache, must-revalidate, max-age=0", "Pragma": "no-cache", and "Expires": "0".
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flask-Appbuilder