Improper Access Control Affecting flask-cors package, versions [4.0.0,5.0.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.08% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Access Control vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-FLASKCORS-7707876
  • published19 Aug 2024
  • disclosed18 Aug 2024
  • credittomorrowisnew_

Introduced: 18 Aug 2024

CVE-2024-6221  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade Flask-Cors to version 5.0.0 or higher.

Overview

Flask-Cors is an A Flask extension adding a decorator for CORS support

Affected versions of this package are vulnerable to Improper Access Control due to the default configuration of the Access-Control-Allow-Private-Network CORS header. An attacker can expose private network resources to unauthorized external access by leveraging this default setting.

CVSS Scores

version 4.0
version 3.1