QID 981719
QID 981719: Python (pip) Security Update for Flask-User (GHSA-4298-89hc-6rfv)
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4298-89hc-6rfv for updates pertaining to this vulnerability.
Vendor References
- GHSA-4298-89hc-6rfv -
github.com/advisories/GHSA-4298-89hc-6rfv
CVEs related to QID 981719
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4298-89hc-6rfv | Flask-User |
|