Search CVE reports


Toggle filters

11 – 17 of 17 results


CVE-2021-33026

Medium priority
Ignored

The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g.,...

1 affected package

flask-caching

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flask-caching Not affected Not affected Not affected Not in release
Show less packages

CVE-2021-32618

Low priority
Ignored

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions...

1 affected package

flask-security

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flask-security Ignored Ignored Ignored Ignored
Show less packages

CVE-2021-23385

Medium priority

Some fixes available 3 of 8

This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing...

1 affected package

flask-security

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flask-security Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-21241

Medium priority
Ignored

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security....

1 affected package

flask-security

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flask-security Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-25032

Medium priority

Some fixes available 1 of 2

An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

1 affected package

python-flask-cors

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-flask-cors Not affected Fixed Not in release
Show less packages

CVE-2019-1010083

Low priority
Needs evaluation

The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.

1 affected package

flask

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flask Not affected Not affected Not affected Needs evaluation
Show less packages

CVE-2018-1000656

Low priority
Fixed

The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be...

1 affected package

flask

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
flask Not affected Fixed
Show less packages