CVE-2024-45314
CVE-2024-45314
Título es
CVE-2024-45314
Mié, 04/09/2024 – 16:15
Tipo
CWE-525
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-45314
Descripción en
Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for `/login` per the directions provided in the GitHub Security Advisory.
04/09/2024
04/09/2024
Vector CVSS:3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
3.60
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
LOW
Referencias
Enviar en el boletín
Off