HIGH 7.5 PyPI

Flask-AppBuilder Has No Rate Limiting on Login AUTH DB

GHSA-9hcr-9hcv-x6pv · CVE-2023-29005 · PYSEC-2026-1380

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Lack of rate limiting will allow an attacker to brute-force user credentials.

Patches

Ability to enable rate limiting on Flask-AppBuilder >= 4.3.0. Use AUTH_RATE_LIMITED = True and RATELIMIT_ENABLED = True set the limit itself by using AUTH_RATE_LIMIT. Will apply only to database authentication.

Workarounds

Implement rate limiting using a reverse proxy or other strategies.

Ready to move

Start Securing

Free, no credit card | First findings in minutes