CVE-2024-6221High· 7.5▾ TwilightFlask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.7%
0.7% → 0.7%
Last analysed / modified upstream
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the Access-Control-Allow-Private-Network CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
flask-cors < 4.0.2Upgrade to a patched release:
flask-cors 4.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2020-25032High· 7.5Flask-Cors Directory Traversal vulnerability
CVE-2024-1681Medium· 5.3flask-cors vulnerable to log injection when the log level is set to debug
CVE-2024-6844Medium· 5.3Flask-CORS allows for inconsistent CORS matching
CVE-2024-6839Medium· 4.3Flask-CORS improper regex path matching vulnerability
CVE-2024-6866Medium· 5.3Flask-CORS vulnerable to Improper Handling of Case Sensitivity