Observable Response Discrepancy in Flask-AppBuilder
Moderate severity
GitHub Reviewed
Published
May 24, 2021
in
dpgaspar/Flask-AppBuilder
•
Updated Sep 20, 2024
Description
Reviewed
May 25, 2021
Published to the GitHub Advisory Database
May 27, 2021
Published by the National Vulnerability Database
Jun 7, 2021
Last updated
Sep 20, 2024
Impact
User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in.
Patches
Upgrade to 3.3.0
For more information
If you have any questions or comments about this advisory:
References