Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2021-12-09T16:40:11
Updated: 2024-08-04T03:08:31.645Z
Reserved: 2021-09-15T00:00:00
Link: CVE-2021-41265
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-12-09T17:15:07.963
Modified: 2024-11-21T06:25:55.307
Link: CVE-2021-41265
Redhat
No data.