Ubuntu 6019-1: Flask-CORS vulnerability | LinuxSecurity.com
==========================================================================
Ubuntu Security Notice USN-6019-1
April 13, 2023

python-flask-cors vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS

Summary:

Applications using Flask-CORS could be made to expose sensitive
information.

Software Description:
- python-flask-cors: Flask extension for handling Cross Origin Resource Sharing (CORS)

Details:

It was discovered that Flask-CORS did not properly escape paths before
evaluating resource rules. An attacker could possibly use this to
expose sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  python3-flask-cors              3.0.8-2ubuntu0.1

After a standard system update you need to restart application using
Flask-CORS to make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-6019-1
  CVE-2020-25032

Package Information:
  https://launchpad.net/ubuntu/+source/python-flask-cors/3.0.8-2ubuntu0.1

Ubuntu 6019-1: Flask-CORS vulnerability

April 13, 2023
Applications using Flask-CORS could be made to expose sensitive information.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Applications using Flask-CORS could be made to expose sensitive information. Software Description: - python-flask-cors: Flask extension for handling Cross Origin Resource Sharing (CORS) Details: It was discovered that Flask-CORS did not properly escape paths before evaluating resource rules. An attacker could possibly use this to expose sensitive information.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: python3-flask-cors 3.0.8-2ubuntu0.1 After a standard system update you need to restart application using Flask-CORS to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6019-1

CVE-2020-25032

Severity
Ubuntu Security Notice USN-6019-1

Package Information

https://launchpad.net/ubuntu/+source/python-flask-cors/3.0.8-2ubuntu0.1

We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.