VDB
CVE-2021-21241
CVE-2021-21241
PUBLISHED
CVSS 7.400000095367432 HIGH
CSRF can expose users authentication token
EPSS 0.42% · 62.4th percentile
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
EPSS Score
0.42%
62.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | Flask-Security-Too | 3.3.0 |
| flask-security-too_project | flask-security-too | 3.3.0 |
| Flask-Middleware | flask-security-too | >= 3.3.0, < 3.4.5 |
Timeline
- Jan 11, 2021 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
References
- https://github.com/Flask-Middleware/flask-security/security/advisories/GHSA-hh7m-rx4f-4vpv url
- https://github.com/Flask-Middleware/flask-security/pull/422 url
- https://github.com/Flask-Middleware/flask-security/commit/61d313150b5f620d0b800896c4f2199005e84b1f url
- https://github.com/Flask-Middleware/flask-security/commit/6d50ee9169acf813257c37b75babe9c28e83542a url
- https://github.com/Flask-Middleware/flask-security/releases/tag/3.4.5 url
- https://pypi.org/project/Flask-Security-Too url
- https://nvd.nist.gov/vuln/detail/CVE-2021-21241 advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/flask-security-too/PYSEC-2021-91.yaml url
- https://web.archive.org/web/20210118165844/https://github.com/Flask-Middleware/flask-security/releases/tag/3.4.5 url
- https://web.archive.org/web/20210118165958/https://github.com/Flask-Middleware/flask-security/commit/6d50ee9169acf813257c37b75babe9c28e83542a url
- https://web.archive.org/web/20210118170445/https://github.com/Flask-Middleware/flask-security/commit/61d313150b5f620d0b800896c4f2199005e84b1f url
- https://web.archive.org/web/20210118170502/https://github.com/Flask-Middleware/flask-security/security/advisories/GHSA-hh7m-rx4f-4vpv url
- https://web.archive.org/web/20211207005640/https://github.com/Flask-Middleware/flask-security/pull/422 url