Vulnerability Description
Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This is fixed in version 0.5.1.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Flask-Restx Project | Flask-Restx | < 0.5.1 |
| Fedoraproject | Fedora | 33 |
Related Weaknesses (CWE)
References
- https://github.com/advisories/GHSA-3q6g-vf58-7m4gThird Party Advisory
- https://github.com/python-restx/flask-restx/blob/fd99fe11a88531f5f3441a278f70205PatchThird Party Advisory
- https://github.com/python-restx/flask-restx/commit/bab31e085f355dd73858fd3715f7ePatchThird Party Advisory
- https://github.com/python-restx/flask-restx/issues/372Issue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://pypi.org/project/flask-restx/ProductThird Party Advisory
- https://github.com/advisories/GHSA-3q6g-vf58-7m4gThird Party Advisory
- https://github.com/python-restx/flask-restx/blob/fd99fe11a88531f5f3441a278f70205PatchThird Party Advisory
- https://github.com/python-restx/flask-restx/commit/bab31e085f355dd73858fd3715f7ePatchThird Party Advisory
- https://github.com/python-restx/flask-restx/issues/372Issue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://pypi.org/project/flask-restx/ProductThird Party Advisory
FAQ
What is CVE-2021-32838?
CVE-2021-32838 is a vulnerability with a CVSS score of 7.5 (HIGH). Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This...
How severe is CVE-2021-32838?
CVE-2021-32838 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32838?
Check the references section above for vendor advisories and patch information. Affected products include: Flask-Restx Project Flask-Restx, Fedoraproject Fedora.