Description
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5564 | Flask-AppBuilder Observable Response Discrepancy |
Github GHSA |
GHSA-p8q5-cvwx-wvwp | Flask-AppBuilder Observable Response Discrepancy |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 03 Mar 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3. | |
| Title | Observable Response Discrepancy in flask-appbuilder | |
| Weaknesses | CWE-204 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-03T18:41:23.427Z
Reserved: 2025-01-16T17:31:06.459Z
Link: CVE-2025-24023
Updated: 2025-03-03T18:41:18.673Z
Status : Received
Published: 2025-03-03T16:15:41.820
Modified: 2025-03-03T16:15:41.820
Link: CVE-2025-24023
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:16Z
Weaknesses
EUVD
Github GHSA