cbcvebase.
CVE-2021-41265
published 2021-12-09

CVE-2021-41265: Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The…

PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.25%
65.9th percentile
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This only affects non database authentication types and new REST API endpoints. Users should upgrade to Flask-AppBuilder 3.3.4 to receive a patch.

Affected

3 ranges
VendorProductVersion rangeFixed in
dpgasparflask-appbuilder< 3.3.43.3.4
dpgasparflask-appbuilder>= 0 < eba517aab121afa3f3f2edb011ec6bc4efd61fbceba517aab121afa3f3f2edb011ec6bc4efd61fbc
dpgasparflask-appbuilder>= 0 < 3.3.43.3.4

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.