CVE-2021-41265
published 2021-12-09CVE-2021-41265: Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The…
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.25%
65.9th percentile
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dpgaspar | flask-appbuilder | < 3.3.4 | 3.3.4 |
| dpgaspar | flask-appbuilder | >= 0 < eba517aab121afa3f3f2edb011ec6bc4efd61fbc | eba517aab121afa3f3f2edb011ec6bc4efd61fbc |
| dpgaspar | flask-appbuilder | >= 0 < 3.3.4 | 3.3.4 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-41265: Flask-AppBuilder is a development framework built on top of Flask
osv·2021-12-09
CVE-2021-41265 CVE-2021-41265: Flask-AppBuilder is a development framework built on top of Flask
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.
GHSA
Improper Authentication in Flask-AppBuilder
ghsa·2021-12-09
CVE-2021-41265 [HIGH] CWE-287 Improper Authentication in Flask-AppBuilder
Improper Authentication in Flask-AppBuilder
### Impact
Improper authentication on the REST API. Allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. Only affects non database authentication types, and new REST API endpoints.
### Patches
Upgrade to Flask-AppBuilder 3.3.4
### For more information
If you have any questions or comments about this advisory:
* Open an issue in https://github.com/dpgaspar/Flask-AppBuilder
OSV
Improper Authentication in Flask-AppBuilder
osv·2021-12-09
CVE-2021-41265 [HIGH] Improper Authentication in Flask-AppBuilder
Improper Authentication in Flask-AppBuilder
### Impact
Improper authentication on the REST API. Allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. Only affects non database authentication types, and new REST API endpoints.
### Patches
Upgrade to Flask-AppBuilder 3.3.4
### For more information
If you have any questions or comments about this advisory:
* Open an issue in https://github.com/dpgaspar/Flask-AppBuilder
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/dpgaspar/Flask-AppBuilder/commit/eba517aab121afa3f3f2edb011ec6bc4efd61fbchttps://github.com/dpgaspar/Flask-AppBuilder/releases/tag/v3.3.4https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-m3rf-7m4w-r66qhttps://github.com/dpgaspar/Flask-AppBuilder/commit/eba517aab121afa3f3f2edb011ec6bc4efd61fbchttps://github.com/dpgaspar/Flask-AppBuilder/releases/tag/v3.3.4https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-m3rf-7m4w-r66q
2021-12-09
Published