Moderate severityGHSA Advisory· Published Jul 5, 2021· Updated Sep 16, 2024
Open Redirect
CVE-2021-23401
Description
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Flask-UserPyPI | <= 1.0.2.2 | — |
Affected products
2- Range: <= 1.0.2.2
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-4298-89hc-6rfvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23401ghsaADVISORY
- github.com/lingthio/Flask-User/blob/master/flask_user/user_manager__utils.pyghsax_refsource_MISCWEB
- github.com/pypa/advisory-database/tree/main/vulns/flask-user/PYSEC-2021-337.yamlghsaWEB
- snyk.io/vuln/SNYK-PYTHON-FLASKUSER-1293188ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.