diff --git a/advisories/github-reviewed/2021/05/GHSA-434h-p4gx-jm89/GHSA-434h-p4gx-jm89.json b/advisories/github-reviewed/2021/05/GHSA-434h-p4gx-jm89/GHSA-434h-p4gx-jm89.json index a50e39365fa..888d82c9711 100644 --- a/advisories/github-reviewed/2021/05/GHSA-434h-p4gx-jm89/GHSA-434h-p4gx-jm89.json +++ b/advisories/github-reviewed/2021/05/GHSA-434h-p4gx-jm89/GHSA-434h-p4gx-jm89.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-434h-p4gx-jm89", - "modified": "2024-09-20T17:16:16Z", + "modified": "2025-03-07T19:08:59Z", "published": "2021-05-27T18:38:36Z", "aliases": [ "CVE-2021-29621" ], "summary": "Observable Response Discrepancy in Flask-AppBuilder", - "details": "### Impact\nUser enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in.\n\n### Patches\nUpgrade to 3.3.0\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Flask-AppBuilder](https://github.com/dpgaspar/Flask-AppBuilder)\n\n", + "details": "### Impact\nUser enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in.\n\n### Patches\nUpgrade to 3.3.0\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Flask-AppBuilder](https://github.com/dpgaspar/Flask-AppBuilder)", "severity": [ { "type": "CVSS_V3", @@ -60,14 +60,26 @@ "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/flask-appbuilder/PYSEC-2021-90.yaml" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r466759f377651f0a690475d5a52564d0e786e82c08d5a5730a4f8352%40%3Cannounce.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r466759f377651f0a690475d5a52564d0e786e82c08d5a5730a4f8352@%3Cannounce.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r5b754118ba4e996adf03863705d34168bffec202da5c6bdc9bf3add5%40%3Cannounce.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r5b754118ba4e996adf03863705d34168bffec202da5c6bdc9bf3add5@%3Cannounce.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r91067f953906d93aaa1c69fe2b5472754019cc6bd4f1ba81349d62a0%40%3Ccommits.airflow.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r91067f953906d93aaa1c69fe2b5472754019cc6bd4f1ba81349d62a0@%3Ccommits.airflow.apache.org%3E" diff --git a/advisories/github-reviewed/2021/09/GHSA-624f-cqvr-3qw4/GHSA-624f-cqvr-3qw4.json b/advisories/github-reviewed/2021/09/GHSA-624f-cqvr-3qw4/GHSA-624f-cqvr-3qw4.json index d5221f1cbaf..2078f9e9965 100644 --- a/advisories/github-reviewed/2021/09/GHSA-624f-cqvr-3qw4/GHSA-624f-cqvr-3qw4.json +++ b/advisories/github-reviewed/2021/09/GHSA-624f-cqvr-3qw4/GHSA-624f-cqvr-3qw4.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-624f-cqvr-3qw4", - "modified": "2024-11-18T16:26:15Z", + "modified": "2025-03-07T19:09:11Z", "published": "2021-09-08T21:11:14Z", "aliases": [ "CVE-2021-32805" ], "summary": "Flask-AppBuilder Open Redirect vulnerability", - "details": "### Impact\nIf using Flask-AppBuilder OAuth, an attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-AppBuilder, this URL can redirect a user to a malicious site. This is an open redirect vulnerability \n\n### Patches\nInstall Flask-AppBuilder 3.2.2 or above\n\n### Workarounds\nFilter HTTP traffic containing `?next={next-site}` where the `next-site` domain is different from the application you are protecting\n", + "details": "### Impact\nIf using Flask-AppBuilder OAuth, an attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-AppBuilder, this URL can redirect a user to a malicious site. This is an open redirect vulnerability \n\n### Patches\nInstall Flask-AppBuilder 3.2.2 or above\n\n### Workarounds\nFilter HTTP traffic containing `?next={next-site}` where the `next-site` domain is different from the application you are protecting", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2021/12/GHSA-m3rf-7m4w-r66q/GHSA-m3rf-7m4w-r66q.json b/advisories/github-reviewed/2021/12/GHSA-m3rf-7m4w-r66q/GHSA-m3rf-7m4w-r66q.json index fd921398c40..f4d2056780e 100644 --- a/advisories/github-reviewed/2021/12/GHSA-m3rf-7m4w-r66q/GHSA-m3rf-7m4w-r66q.json +++ b/advisories/github-reviewed/2021/12/GHSA-m3rf-7m4w-r66q/GHSA-m3rf-7m4w-r66q.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-m3rf-7m4w-r66q", - "modified": "2024-09-20T17:43:41Z", + "modified": "2025-03-07T19:09:17Z", "published": "2021-12-09T19:09:07Z", "aliases": [ "CVE-2021-41265" ], "summary": "Improper Authentication in Flask-AppBuilder", - "details": "### Impact\nImproper authentication on the REST API. Allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. Only affects non database authentication types, and new REST API endpoints.\n\n### Patches\nUpgrade to Flask-AppBuilder 3.3.4\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/dpgaspar/Flask-AppBuilder\n", + "details": "### Impact\nImproper authentication on the REST API. Allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. Only affects non database authentication types, and new REST API endpoints.\n\n### Patches\nUpgrade to Flask-AppBuilder 3.3.4\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in https://github.com/dpgaspar/Flask-AppBuilder", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2022/02/GHSA-wfjw-w6pv-8p7f/GHSA-wfjw-w6pv-8p7f.json b/advisories/github-reviewed/2022/02/GHSA-wfjw-w6pv-8p7f/GHSA-wfjw-w6pv-8p7f.json index 8e334be3b73..8928cdb7616 100644 --- a/advisories/github-reviewed/2022/02/GHSA-wfjw-w6pv-8p7f/GHSA-wfjw-w6pv-8p7f.json +++ b/advisories/github-reviewed/2022/02/GHSA-wfjw-w6pv-8p7f/GHSA-wfjw-w6pv-8p7f.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-wfjw-w6pv-8p7f", - "modified": "2024-09-20T16:49:31Z", + "modified": "2025-03-07T19:09:24Z", "published": "2022-02-01T00:47:53Z", "aliases": [ "CVE-2022-21659" ], "summary": "Observable Response Discrepancy in Flask-AppBuilder", - "details": "### Impact\nUser enumeration in database authentication in Flask-AppBuilder < 3.4.4. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in.\n\n### Patches\nUpgrade to 3.4.4\n\n### Workarounds\n\n### References\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [example link to repo](http://example.com)\n* Email us at [example email address](mailto:example@example.com)\n", + "details": "### Impact\nUser enumeration in database authentication in Flask-AppBuilder < 3.4.4. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in.\n\n### Patches\nUpgrade to 3.4.4\n\n### Workarounds\n\n### References\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [example link to repo](http://example.com)\n* Email us at [example email address](mailto:example@example.com)", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2022/07/GHSA-32ff-4g79-vgfc/GHSA-32ff-4g79-vgfc.json b/advisories/github-reviewed/2022/07/GHSA-32ff-4g79-vgfc/GHSA-32ff-4g79-vgfc.json index 910cdca1840..6d7ef7fe1db 100644 --- a/advisories/github-reviewed/2022/07/GHSA-32ff-4g79-vgfc/GHSA-32ff-4g79-vgfc.json +++ b/advisories/github-reviewed/2022/07/GHSA-32ff-4g79-vgfc/GHSA-32ff-4g79-vgfc.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-32ff-4g79-vgfc", - "modified": "2022-08-10T23:50:57Z", + "modified": "2025-03-07T19:09:38Z", "published": "2022-07-29T22:28:12Z", "aliases": [ "CVE-2022-31177" ], "summary": "Flask-AppBuilder before v4.1.3 allows inference of sensitive information through query strings", - "details": "### Impact\nAn authenticated Admin user could craft HTTP requests to filter users by their salted and hashed passwords strings. These filters could be made by using partial hashed password strings. The response would not include the hashed passwords, but an attacker could infer partial password hashes and their respective users.\n\nOnly when using `AUTH_DB` database authentication option.\n\n### Patches\nFixed on 4.1.3\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [example link to repo](http://example.com)\n* Email us at [example email address](mailto:example@example.com)\n", + "details": "### Impact\nAn authenticated Admin user could craft HTTP requests to filter users by their salted and hashed passwords strings. These filters could be made by using partial hashed password strings. The response would not include the hashed passwords, but an attacker could infer partial password hashes and their respective users.\n\nOnly when using `AUTH_DB` database authentication option.\n\n### Patches\nFixed on 4.1.3\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [example link to repo](http://example.com)\n* Email us at [example email address](mailto:example@example.com)", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/04/GHSA-9hcr-9hcv-x6pv/GHSA-9hcr-9hcv-x6pv.json b/advisories/github-reviewed/2023/04/GHSA-9hcr-9hcv-x6pv/GHSA-9hcr-9hcv-x6pv.json index b519a5eab8b..74fcbee5512 100644 --- a/advisories/github-reviewed/2023/04/GHSA-9hcr-9hcv-x6pv/GHSA-9hcr-9hcv-x6pv.json +++ b/advisories/github-reviewed/2023/04/GHSA-9hcr-9hcv-x6pv/GHSA-9hcr-9hcv-x6pv.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-9hcr-9hcv-x6pv", - "modified": "2023-04-19T17:12:23Z", + "modified": "2025-03-07T19:09:34Z", "published": "2023-04-10T16:37:40Z", "aliases": [ "CVE-2023-29005" ], "summary": "Flask-AppBuilder Has No Rate Limiting on Login AUTH DB", - "details": "### Impact\nLack of rate limiting will allow an attacker to brute-force user credentials.\n\n### Patches\nAbility to enable rate limiting on Flask-AppBuilder >= 4.3.0. Use `AUTH_RATE_LIMITED = True` and `RATELIMIT_ENABLED = True` set the limit itself by using `AUTH_RATE_LIMIT`. Will apply only to database authentication.\n\n### Workarounds\nImplement rate limiting using a reverse proxy or other strategies. ", + "details": "### Impact\nLack of rate limiting will allow an attacker to brute-force user credentials.\n\n### Patches\nAbility to enable rate limiting on Flask-AppBuilder >= 4.3.0. Use `AUTH_RATE_LIMITED = True` and `RATELIMIT_ENABLED = True` set the limit itself by using `AUTH_RATE_LIMIT`. Will apply only to database authentication.\n\n### Workarounds\nImplement rate limiting using a reverse proxy or other strategies.", "severity": [ { "type": "CVSS_V3",