Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 10: DLA-3545-1 Critical: Flask-Security URL Bypass Issue

debian lts
Calendar Grey August 28, 2023
Dist Debian Esm H88
Django-Auth vulnerability permits path evasion; Ubuntu LTS recommends patch installation to reduce threats. Protect your applications immediately!
It was discovered that when using the get_post_logout_redirect and get_post_login_redirect functions in flask-security, an implementation of simple security for Flask apps, it is p...

Summary

This vulnerability is exploitable only if an alternative WSGI server
other than Werkzeug is used, or the default behaviour of Werkzeug is
modified using 'autocorrect_location_header=False.

For Debian 10 buster, this problem has been fixed in version
1.7.5-2+deb10u1.

We recommend that you upgrade your flask-security packages.

For the detailed security status of flask-security please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/flask-security

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
critical
Lowest
Low
Medium
High
Critical

Package: flask-security
Version: 1.7.5-2+deb10u1
CVE ID: CVE-2021-23385
Debian Bug: 1021279

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here