QID 981684

QID 981684: Python (pip) Security Update for flask (GHSA-5wv5-4vpf-pj6m)

The Pallets Project Flask before 1.0 is affected by unexpected memory usage. The impact is denial of service. The attack vector is crafted encoded JSON data. The fixed version is 1. NOTE this may overlap CVE-2018-1000656.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-5wv5-4vpf-pj6m for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981684

    Software Advisories
    Advisory ID Software Component Link
    GHSA-5wv5-4vpf-pj6m flask URL Logo github.com/advisories/GHSA-5wv5-4vpf-pj6m