Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0061 | Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default |
Github GHSA |
GHSA-hxwh-jpp2-84pm | Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default |
Ubuntu USN |
USN-7612-1 | Flask-CORS vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 07 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions. | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions. |
| References |
|
Tue, 20 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other | |
| Metrics |
cvssV3_1
|
Mon, 19 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Corydolphin
Corydolphin flask-cors |
|
| CPEs | cpe:2.3:a:corydolphin:flask-cors:4.0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Corydolphin
Corydolphin flask-cors |
|
| Metrics |
ssvc
|
Sun, 18 Aug 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions. | |
| Title | Improper Access Control in corydolphin/flask-cors | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-04-07T15:03:37.262Z
Reserved: 2024-06-20T18:32:12.417Z
Link: CVE-2024-6221
Updated: 2024-08-19T13:48:08.219Z
Status : Modified
Published: 2024-08-18T19:15:04.730
Modified: 2025-04-07T15:15:42.060
Link: CVE-2024-6221
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN