Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5564 | Flask-AppBuilder Observable Response Discrepancy |
Github GHSA |
GHSA-p8q5-cvwx-wvwp | Flask-AppBuilder Observable Response Discrepancy |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Mar 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3. | |
| Title | Observable Response Discrepancy in flask-appbuilder | |
| Weaknesses | CWE-204 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-03T18:41:23.427Z
Reserved: 2025-01-16T17:31:06.459Z
Link: CVE-2025-24023
Updated: 2025-03-03T18:41:18.673Z
Status : Received
Published: 2025-03-03T16:15:41.820
Modified: 2025-03-03T16:15:41.820
Link: CVE-2025-24023
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:16Z
EUVD
Github GHSA