QID 982812
QID 982812: Python (pip) Security Update for webargs (GHSA-fjq3-5pxw-4wj4)
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fjq3-5pxw-4wj4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-fjq3-5pxw-4wj4 -
github.com/advisories/GHSA-fjq3-5pxw-4wj4
CVEs related to QID 982812
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fjq3-5pxw-4wj4 | webargs |
|