Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for `/login` per the directions provided in the GitHub Security Advisory.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dpgaspar
Dpgaspar flask App Builder |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:dpgaspar:flask_app_builder:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dpgaspar
Dpgaspar flask App Builder |
Wed, 04 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 04 Sep 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for `/login` per the directions provided in the GitHub Security Advisory. | |
Title | Flask-AppBuilder login form allows browser to cache sensitive fields | |
Weaknesses | CWE-525 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-09-04T16:08:41.004Z
Updated: 2024-09-04T17:43:05.895Z
Reserved: 2024-08-26T18:25:35.444Z
Link: CVE-2024-45314
Vulnrichment
Updated: 2024-09-04T17:42:26.850Z
NVD
Status : Analyzed
Published: 2024-09-04T16:15:08.833
Modified: 2024-09-12T16:39:53.690
Link: CVE-2024-45314
Redhat
No data.