CVE-2019-1010083 PUBLISHED

The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.

EPSS 0.40% · 60.4th percentile

Risk Scores

EPSS Score
0.40%
60.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSflask0, 0.12.2-2, 0.12.2-3
Ubuntu:16.04:LTSflask0.10.1-2build2, 0.10.1-2ubuntu0.1, 0

Timeline

References

Open in Interactive Console →