CVE-2025-24023Low· 3.7▾ SunlitFlask-AppBuilder Observable Response Discrepancy
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
User enumeration in database authentication in Flask-AppBuilder <= 4.5.3 and werkzeug >= 3.0.0. Allows for a non authenticated user to enumerate existing usernames by timing the response time from the server when brute forcing requests to login.
Upgrade to flask-appbuilder>=4.5.3
Downgrade werkzeug to <3.0.0
Are there any links users can visit to find out more?
flask-appbuilder < 4.5.3Upgrade to a patched release:
flask-appbuilder 4.5.3Connected by shared product, vendor, weakness, or advisory.
CVE-2022-21659Medium· 5.3Observable Response Discrepancy in Flask-AppBuilder
CVE-2024-25128Critical· 9.1Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
CVE-2021-41265High· 8.1Improper Authentication in Flask-AppBuilder
CVE-2024-45314Low· 3.6Flask-AppBuilder's login form allows browser to cache sensitive fields
CVE-2024-27083Medium· 4.3Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)
CVE-2023-29005High· 7.5Flask-AppBuilder Has No Rate Limiting on Login AUTH DB