HIGH 8.1 PyPI
Improper Authentication in Flask-AppBuilder
GHSA-m3rf-7m4w-r66q · CVE-2021-41265 · PYSEC-2021-851
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Improper authentication on the REST API. Allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. Only affects non database authentication types, and new REST API endpoints.
Patches
Upgrade to Flask-AppBuilder 3.3.4
For more information
If you have any questions or comments about this advisory:
- Open an issue in https://github.com/dpgaspar/Flask-AppBuilder
References
- WEB https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-m3rf-7m4w-r66q
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-41265
- WEB https://github.com/dpgaspar/Flask-AppBuilder/commit/eba517aab121afa3f3f2edb011ec6bc4efd61fbc
- PACKAGE https://github.com/dpgaspar/Flask-AppBuilder
- WEB https://github.com/dpgaspar/Flask-AppBuilder/releases/tag/v3.3.4
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/flask-appbuilder/PYSEC-2021-851.yaml
Ready to move
Start Securing
Free, no credit card | First findings in minutes