LOW 3.6 PyPI

Flask-AppBuilder's login form allows browser to cache sensitive fields

GHSA-fw5r-6m3x-rh7p · CVE-2024-45314 · PYSEC-2026-1382

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources.

Patches

Upgrade flask-appbuilder to version 4.5.1

Workarounds

If upgrading is not possible configure your web server to send the following HTTP headers for /login:
"Cache-Control": "no-store, no-cache, must-revalidate, max-age=0"
"Pragma": "no-cache"
"Expires": "0"

Ready to move

Start Securing

Free, no credit card | First findings in minutes