CVE-2022-21659
Observable Response Discrepancy in Flask-AppBuilder
5.3
MEDIUM
CVSS 3.1
EPSS 0.95%
描述
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Users are advised to upgrade to version 3.4.4 as soon as possible. There are no known workarounds for this issue.
如何修補 CVE-2022-21659
要修補 CVE-2022-21659,請將受影響套件升級到下列已修補版本。
- —升級至 3.4.4 或更新版本
- —升級至 3.4.2 或更新版本
CVE-2022-21659 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 3.4.4
- from 0, < 3.4.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |