Metrics
Affected Vendors & Products
Mon, 07 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions. | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions. |
References |
|
Tue, 20 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-Other | |
Metrics |
cvssV3_1
|
Mon, 19 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Corydolphin
Corydolphin flask-cors |
|
CPEs | cpe:2.3:a:corydolphin:flask-cors:4.0.1:*:*:*:*:*:*:* | |
Vendors & Products |
Corydolphin
Corydolphin flask-cors |
|
Metrics |
ssvc
|
Sun, 18 Aug 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions. | |
Title | Improper Access Control in corydolphin/flask-cors | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-04-07T15:03:37.262Z
Reserved: 2024-06-20T18:32:12.417Z
Link: CVE-2024-6221

Updated: 2024-08-19T13:48:08.219Z

Status : Modified
Published: 2024-08-18T19:15:04.730
Modified: 2025-04-07T15:15:42.060
Link: CVE-2024-6221

No data.