Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhjM3AtZmYzbS1mNDZ2
Flask-Cors Directory Traversal vulnerability
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../
directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhjM3AtZmYzbS1mNDZ2
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 3 years ago
Updated: 8 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-xc3p-ff3m-f46v, CVE-2020-25032
References:
- https://nvd.nist.gov/vuln/detail/CVE-2020-25032
- https://github.com/corydolphin/flask-cors/commit/67c4b2cc98ae87cf1fa7df4f97fd81b40c79b895
- https://github.com/corydolphin/flask-cors/releases/tag/3.0.9
- https://www.debian.org/security/2020/dsa-4775
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00039.html
- http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00048.html
- https://github.com/advisories/GHSA-xc3p-ff3m-f46v
Blast Radius: 32.1
Affected Packages
pypi:Flask-Cors
Dependent packages: 328Dependent repositories: 18,926
Downloads: 9,056,695 last month
Affected Version Ranges: < 3.0.9
Fixed in: 3.0.9
All affected versions: 1.1.1, 1.1.2, 1.1.3, 1.2.0, 1.2.1, 1.3.0, 1.3.1, 1.4.0, 1.5.0, 1.6.0, 1.6.1, 1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.8.0, 1.8.1, 1.9.0, 1.10.0, 1.10.1, 1.10.2, 1.10.3, 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.6, 3.0.7, 3.0.8
All unaffected versions: 3.0.9, 3.0.10, 4.0.0