CVE-2023-30861High· 7.5▾ MidnightPoC availableFlask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.3 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.3%
1 GitHub repo (last check)
When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by a proxy to other clients. If the proxy also caches Set-Cookie headers, it may send one client's session cookie to other clients. The severity depends on the application's use of the session, and the proxy's behavior regarding cookies. The risk depends on all these conditions being met.
session.permanent = True.SESSION_REFRESH_EACH_REQUEST is enabled (the default).Cache-Control header to indicate that a page is private or should not be cached.This happens because vulnerable versions of Flask only set the Vary: Cookie header when the session is accessed or modified, not when it is refreshed (re-sent to update the expiration) without being accessed or modified.
flask >= 2.3.0, < 2.3.2flask < 2.2.5Upgrade to a patched release:
flask 2.3.2flask 2.2.5Connected by shared product, vendor, weakness, or advisory.