Dpgaspar

Flask-appbuilder

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 11.09.2025 17:55:48
  • Zuletzt bearbeitet 24.09.2025 13:41:42

Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other non-database authentication methods, the password reset endpoint remains registered and accessible, des...

  • EPSS 0.05%
  • Veröffentlicht 16.05.2025 13:51:55
  • Zuletzt bearbeitet 19.09.2025 18:04:24

Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-AppBuilder 4...

  • EPSS 0.06%
  • Veröffentlicht 03.03.2025 16:15:41
  • Zuletzt bearbeitet 07.03.2025 19:37:57

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerabili...

  • EPSS 0.63%
  • Veröffentlicht 29.02.2024 01:44:19
  • Zuletzt bearbeitet 01.04.2025 15:22:28

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth log...

  • EPSS 0.4%
  • Veröffentlicht 29.02.2024 01:44:14
  • Zuletzt bearbeitet 21.11.2024 09:00:18

Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID servic...

  • EPSS 0.25%
  • Veröffentlicht 10.04.2023 21:15:07
  • Zuletzt bearbeitet 07.03.2025 14:37:51

Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`, and settin...

  • EPSS 0.36%
  • Veröffentlicht 01.08.2022 19:15:08
  • Zuletzt bearbeitet 07.03.2025 14:37:51

Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These filters could be made ...

  • EPSS 0.35%
  • Veröffentlicht 24.03.2022 20:15:09
  • Zuletzt bearbeitet 07.03.2025 14:37:51

Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in ...

  • EPSS 0.26%
  • Veröffentlicht 31.01.2022 21:15:09
  • Zuletzt bearbeitet 05.05.2025 17:17:47

Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accoun...

  • EPSS 0.33%
  • Veröffentlicht 09.12.2021 17:15:07
  • Zuletzt bearbeitet 07.03.2025 14:37:51

Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authen...