VYPR

Flask Cors

by Corydolphin

Source repositories

CVEs (2)

  • CVE-2024-6221HigAug 18, 2024
    risk 0.42cvss 7.5epss 0.01

    A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as…

  • CVE-2024-1681MedApr 19, 2024
    risk 0.27cvss 5.3epss 0.01

    corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. This vulnerability allows attackers to…