QID 983060
QID 983060: Python (pip) Security Update for Flask-Security-Too (GHSA-hh7m-rx4f-4vpv)
Security update has been released for Flask-Security-Too to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Version 3.4.5 and soon to be released 4.0.0 are patched.Workaround:
If you aren't using authentication tokens - you can set the SECURITY_TOKEN_MAX_AGE to "0" (seconds) which should make the token unusable.
If you aren't using authentication tokens - you can set the SECURITY_TOKEN_MAX_AGE to "0" (seconds) which should make the token unusable.
Vendor References
- GHSA-hh7m-rx4f-4vpv -
github.com/advisories/GHSA-hh7m-rx4f-4vpv
CVEs related to QID 983060
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hh7m-rx4f-4vpv | Flask-Security-Too |
|