An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-flask-cors | Oct 21, 2020 | Aug 31, 2020 |
| Freebsd | — | Upgrade py38-Flask-CorsUpgrade py39-Flask-CorsUpgrade py37-Flask-CorsUpgrade py310-Flask-CorsUpgrade py311-Flask-Cors | Sep 1, 2023 | Aug 31, 2023 |
| Suse | — | Upgrade python3-Flask-CorsUpgrade python2-Flask-Cors | Sep 11, 2020 | Aug 31, 2020 |
| Ubuntu | — | Upgrade python3-flask-cors | Apr 17, 2023 | Aug 31, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub