CVE-2024-6221
published 2024-08-18CVE-2024-6221: A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.72%
50.1th percentile
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| corydolphin | corydolphin_flask-cors | >= unspecified < 5.0.0 | 5.0.0 |
| corydolphin | flask-cors | — | — |
| debian | python-flask-cors | < python-flask-cors 5.0.0-1 (forky) | python-flask-cors 5.0.0-1 (forky) |
| flask-cors_project | flask-cors | >= 0 < 4.0.2 | 4.0.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5LOW
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python-flask-cors vulnerabilities
osv·2025-07-02·CVSS 5.3
CVE-2024-6839 [MEDIUM] python-flask-cors vulnerabilities
python-flask-cors vulnerabilities
It was discovered that Flask-CORS did not correctly handle certain regular
expressions. A remote attacker could possibly use this issue to leak
sensitive information or bypass authentication mechanisms. (CVE-2024-6839)
It was discovered that Flask-CORS allowed certain CORS headers to be
enabled by default. A remote attacker could possibly use this issue to leak
sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu
22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2024-6221) It was
discovered that Flask-CORS did not correctly handle case sensitivity when
matching paths. A remote attacker could possibly use this issue to leak
sensitive information. (CVE-2024-6866) It was discovered that Flask-CORS
did not correctly handle certain charact
GHSA
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
ghsa·2024-08-18
CVE-2024-6221 [HIGH] CWE-284 Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
OSV
CVE-2024-6221: A vulnerability in corydolphin/flask-cors version 4
osv·2024-08-18·CVSS 7.5
CVE-2024-6221 [HIGH] CVE-2024-6221: A vulnerability in corydolphin/flask-cors version 4
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
OSV
CVE-2024-6221: A vulnerability in corydolphin/flask-cors up to version 4
osv·2024-08-18
CVE-2024-6221 CVE-2024-6221: A vulnerability in corydolphin/flask-cors up to version 4
A vulnerability in corydolphin/flask-cors up to version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
OSV
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
osv·2024-08-18
CVE-2024-6221 [HIGH] Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
Ubuntu
Flask-CORS vulnerabilities
vendor_ubuntu·2025-07-02·CVSS 5.3
CVE-2024-6839 [MEDIUM] Flask-CORS vulnerabilities
Title: Flask-CORS vulnerabilities
Summary: Several security issues were fixed in Flask-CORS.
It was discovered that Flask-CORS did not correctly handle certain regular
expressions. A remote attacker could possibly use this issue to leak
sensitive information or bypass authentication mechanisms. (CVE-2024-6839)
It was discovered that Flask-CORS allowed certain CORS headers to be
enabled by default. A remote attacker could possibly use this issue to leak
sensitive information. This issue only affected Ubuntu 20.04 LTS, Ubuntu
22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 24.10. (CVE-2024-6221) It was
discovered that Flask-CORS did not correctly handle case sensitivity when
matching paths. A remote attacker could possibly use this issue to leak
sensitive information. (CVE-2024-6866) It was discove
Debian
CVE-2024-6221: python-flask-cors - A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Contr...
vendor_debian·2024·CVSS 7.5
CVE-2024-6221 [HIGH] CVE-2024-6221: python-flask-cors - A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Contr...
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 5.0.0-1)
sid: resolved (fixed in 5.0.0-1)
trixie: resolved (fixed in 5.0.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-18
Published