CVE-2021-41265: Improper Authentication in Flask-AppBuilder
(updated )
Improper authentication on the REST API. Allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. Only affects non database authentication types, and new REST API endpoints.
References
- github.com/advisories/GHSA-m3rf-7m4w-r66q
- github.com/dpgaspar/Flask-AppBuilder
- github.com/dpgaspar/Flask-AppBuilder/commit/eba517aab121afa3f3f2edb011ec6bc4efd61fbc
- github.com/dpgaspar/Flask-AppBuilder/releases/tag/v3.3.4
- github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-m3rf-7m4w-r66q
- github.com/pypa/advisory-database/tree/main/vulns/flask-appbuilder/PYSEC-2021-851.yaml
- nvd.nist.gov/vuln/detail/CVE-2021-41265
Detect and mitigate CVE-2021-41265 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →