A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
History

Tue, 20 Aug 2024 20:00:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-Other
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Mon, 19 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Corydolphin
Corydolphin flask-cors
CPEs cpe:2.3:a:corydolphin:flask-cors:4.0.1:*:*:*:*:*:*:*
Vendors & Products Corydolphin
Corydolphin flask-cors
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 18 Aug 2024 19:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
Title Improper Access Control in corydolphin/flask-cors
Weaknesses CWE-284
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2024-08-18T18:58:20.551Z

Updated: 2024-08-19T13:48:13.411Z

Reserved: 2024-06-20T18:32:12.417Z

Link: CVE-2024-6221

cve-icon Vulnrichment

Updated: 2024-08-19T13:48:08.219Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-18T19:15:04.730

Modified: 2024-08-20T19:37:23.077

Link: CVE-2024-6221

cve-icon Redhat

No data.