Flask-Security@5.5.1

Quickly add security features to your Flask application.

  • latest version

    5.8.1

  • latest non vulnerable version

  • first published

    14 years ago

  • latest version published

    2 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the Flask-Security package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Open Redirect

    Flask-Security is a Simple security for Flask apps.

    Affected versions of this package are vulnerable to Open Redirect via the validate_redirect_url function. An attacker can redirect users to an attacker-controlled domain by crafting a specially formatted URL containing a backslash in the authority component, which bypasses subdomain validation. This is only exploitable if subdomain redirects are enabled in the configuration.

    How to fix Open Redirect?

    Upgrade Flask-Security to version 5.8.1 or higher.

    [,5.8.1)