Safety vulnerability ID: 40630
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Flask-AppBuilder 3.3.0 includes a fix for CVE-2021-29621: User enumeration in database authentication in Flask-AppBuilder <= 3.2.3 allows for a non authenticated users to enumerate existing accounts by timing the response time from the server when you are logging in.
Latest version: 4.6.0
Simple and rapid application development framework, built on top of Flask. includes detailed security, auto CRUD generation for your models, google charts and much more.
Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Upgrade to version 3.3.0 or higher to resolve. See CVE-2021-29621.
CONFIRM:https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-434h-p4gx-jm89: https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-434h-p4gx-jm89
MISC:https://github.com/dpgaspar/Flask-AppBuilder/commit/780bd0e8fbf2d36ada52edb769477e0a4edae580: https://github.com/dpgaspar/Flask-AppBuilder/commit/780bd0e8fbf2d36ada52edb769477e0a4edae580
MISC:https://pypi.org/project/Flask-AppBuilder/: https://pypi.org/project/Flask-AppBuilder/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application