HIGH 7.5 PyPI
Flask-AppBuilder Has No Rate Limiting on Login AUTH DB
GHSA-9hcr-9hcv-x6pv · CVE-2023-29005 · PYSEC-2026-1380
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Lack of rate limiting will allow an attacker to brute-force user credentials.
Patches
Ability to enable rate limiting on Flask-AppBuilder >= 4.3.0. Use AUTH_RATE_LIMITED = True and RATELIMIT_ENABLED = True set the limit itself by using AUTH_RATE_LIMIT. Will apply only to database authentication.
Workarounds
Implement rate limiting using a reverse proxy or other strategies.
References
- WEB https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-9hcr-9hcv-x6pv
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-29005
- WEB https://github.com/dpgaspar/Flask-AppBuilder/pull/1976
- WEB https://flask-limiter.readthedocs.io/en/stable/configuration.html
- PACKAGE https://github.com/dpgaspar/Flask-AppBuilder
- WEB https://github.com/dpgaspar/Flask-AppBuilder/releases/tag/v4.3.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes