CVE-2021-29621Observable Discrepancy in Flask-appbuilder

Severity
5.3MEDIUMNVD
EPSS
0.4%
top 37.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7

Description

Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Upgrade to version 3.3.0 or higher to resolve.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

Patches

🔴Vulnerability Details

4
OSV
CVE-2021-29621: Flask-AppBuilder is a development framework, built on top of Flask2021-06-07
CVEList
Observable Response Discrepancy in Flask-AppBuilder2021-06-07
OSV
Observable Response Discrepancy in Flask-AppBuilder2021-05-27
GHSA
Observable Response Discrepancy in Flask-AppBuilder2021-05-27
CVE-2021-29621 — Observable Discrepancy | cvebase