QID 982058
QID 982058: Python (pip) Security Update for Flask-Unchained (GHSA-pjc4-3w99-j7v4)
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pjc4-3w99-j7v4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-pjc4-3w99-j7v4 -
github.com/advisories/GHSA-pjc4-3w99-j7v4
CVEs related to QID 982058
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pjc4-3w99-j7v4 | Flask-Unchained |
|