CVE-2025-24023
CVE-2025-24023
Título es
CVE-2025-24023
Lun, 03/03/2025 – 16:15
Tipo
CWE-204
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-24023
Descripción en
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.
03/03/2025
03/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
3.70
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
LOW
Referencias
https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-p8q5-cvwx-wvwp
Enviar en el boletín
Off