Vulnerability Description
Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Upgrade to version 3.3.0 or higher to resolve.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dpgaspar | Flask-Appbuilder | <= 3.2.3 |
| Apache | Airflow | 1.10.0 |
Related Weaknesses (CWE)
References
- https://github.com/dpgaspar/Flask-AppBuilder/commit/780bd0e8fbf2d36ada52edb76947PatchThird Party Advisory
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-434h-p4gx-Third Party Advisory
- https://lists.apache.org/thread.html/r466759f377651f0a690475d5a52564d0e786e82c08
- https://lists.apache.org/thread.html/r5b754118ba4e996adf03863705d34168bffec202da
- https://lists.apache.org/thread.html/r91067f953906d93aaa1c69fe2b5472754019cc6bd4
- https://pypi.org/project/Flask-AppBuilder/ProductThird Party Advisory
- https://github.com/dpgaspar/Flask-AppBuilder/commit/780bd0e8fbf2d36ada52edb76947PatchThird Party Advisory
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-434h-p4gx-Third Party Advisory
- https://lists.apache.org/thread.html/r466759f377651f0a690475d5a52564d0e786e82c08
- https://lists.apache.org/thread.html/r5b754118ba4e996adf03863705d34168bffec202da
- https://lists.apache.org/thread.html/r91067f953906d93aaa1c69fe2b5472754019cc6bd4
- https://pypi.org/project/Flask-AppBuilder/ProductThird Party Advisory
FAQ
What is CVE-2021-29621?
CVE-2021-29621 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing ...
How severe is CVE-2021-29621?
CVE-2021-29621 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-29621?
Check the references section above for vendor advisories and patch information. Affected products include: Dpgaspar Flask-Appbuilder, Apache Airflow.