Description
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Users are advised to upgrade to version 3.4.4 as soon as possible. There are no known workarounds for this issue.
Published: 2022-01-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-0103 Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Users are advised to upgrade to version 3.4.4 as soon as possible. There are no known workarounds for this issue.
Github GHSA Github GHSA GHSA-wfjw-w6pv-8p7f Observable Response Discrepancy in Flask-AppBuilder
History

Mon, 05 May 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Dpgaspar
Dpgaspar flask-appbuilder
CPEs cpe:2.3:a:flask-appbuilder_project:flask-appbuilder:*:*:*:*:*:*:*:* cpe:2.3:a:dpgaspar:flask-appbuilder:*:*:*:*:*:*:*:*
Vendors & Products Flask-appbuilder Project
Flask-appbuilder Project flask-appbuilder
Dpgaspar
Dpgaspar flask-appbuilder

Subscriptions

Dpgaspar Flask-appbuilder
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-05-05T16:34:10.131Z

Reserved: 2021-11-16T00:00:00.000Z

Link: CVE-2022-21659

cve-icon Vulnrichment

Updated: 2024-08-03T02:46:39.326Z

cve-icon NVD

Status : Modified

Published: 2022-01-31T21:15:09.013

Modified: 2025-05-05T17:17:47.010

Link: CVE-2022-21659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses