Skip to content

Possible URL Redirection to Untrusted Site ('Open Redirect') in Flask-AppBuilder

Low
dpgaspar published GHSA-2ccw-7px8-vmpf Mar 24, 2022

Package

pip Flask-AppBuilder (pip)

Affected versions

<3.4.4

Patched versions

3.4.5

Description

Impact

Open redirect vulnerability when using database authentication login page on versions bellow 3.4.5

Patches

Upgrade to 3.4.5

Workarounds

May be possible to implement internal security measures to prevent this vulnerability.

References

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2022-24776

Weaknesses