QID 982204
QID 982204: Python (pip) Security Update for Flask-Caching (GHSA-656c-6cxf-hvcv)
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the cache, and execute Python code.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-656c-6cxf-hvcv for updates pertaining to this vulnerability.
Vendor References
- GHSA-656c-6cxf-hvcv -
github.com/advisories/GHSA-656c-6cxf-hvcv
CVEs related to QID 982204
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-656c-6cxf-hvcv | Flask-Caching |
|