Skip to content

Improper Authentication in Flask-AppBuilder

High
dpgaspar published GHSA-m3rf-7m4w-r66q Dec 9, 2021

Package

pip Flask-AppBuilder (pip)

Affected versions

<=3.3.4

Patched versions

3.3.4

Description

Impact

Improper authentication on the REST API. Allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. Only affects non database authentication types, and new REST API endpoints.

Patches

Upgrade to Flask-AppBuilder 3.3.4

Workarounds

References

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-41265

Weaknesses