From 6a316bb9047f27011e551964bafbe87cdd163c8a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 13 May 2025 20:28:40 +0000 Subject: [PATCH] Publish GHSA-4grg-w6v8-c28g --- .../GHSA-4grg-w6v8-c28g.json | 72 +++++++++++++++++++ 1 file changed, 72 insertions(+) create mode 100644 advisories/github-reviewed/2025/05/GHSA-4grg-w6v8-c28g/GHSA-4grg-w6v8-c28g.json diff --git a/advisories/github-reviewed/2025/05/GHSA-4grg-w6v8-c28g/GHSA-4grg-w6v8-c28g.json b/advisories/github-reviewed/2025/05/GHSA-4grg-w6v8-c28g/GHSA-4grg-w6v8-c28g.json new file mode 100644 index 00000000000..60d0c4e671c --- /dev/null +++ b/advisories/github-reviewed/2025/05/GHSA-4grg-w6v8-c28g/GHSA-4grg-w6v8-c28g.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4grg-w6v8-c28g", + "modified": "2025-05-13T20:25:26Z", + "published": "2025-05-13T20:25:26Z", + "aliases": [ + "CVE-2025-47278" + ], + "summary": "Flask uses fallback key instead of current signing key", + "details": "In Flask 3.1.0, the way fallback key configuration was handled resulted in the last fallback key being used for signing, rather than the current signing key.\n\nSigning is provided by the `itsdangerous` library. A list of keys can be passed, and it expects the last (top) key in the list to be the most recent key, and uses that for signing. Flask was incorrectly constructing that list in reverse, passing the signing key first.\n\nSites that have opted-in to use key rotation by setting `SECRET_KEY_FALLBACKS` are likely to unexpectedly be signing their sessions with stale keys, and their transition to fresher keys will be impeded. Sessions are still signed, so this would not cause any sort of data integrity loss.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "flask" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.1.0" + }, + { + "fixed": "3.1.1" + } + ] + } + ], + "versions": [ + "3.1.0" + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pallets/flask/security/advisories/GHSA-4grg-w6v8-c28g" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47278" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/flask/commit/73d6504063bfa00666a92b07a28aaf906c532f09" + }, + { + "type": "PACKAGE", + "url": "https://github.com/pallets/flask" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/flask/releases/tag/3.1.1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-683" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-05-13T20:25:26Z", + "nvd_published_at": "2025-05-13T16:15:32Z" + } +} \ No newline at end of file