VDB

CVE-2021-23385

CVE-2021-23385 PUBLISHED

This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False. **Note:** Flask-Security is not maintained anymore.

EPSS 0.19% · 40.0th percentile

Risk Scores

EPSS Score
0.19%
40.0th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSflask-security0, 1.7.5-2
Ubuntu:Pro:18.04:LTSflask-security0, 1.7.5-2, 1.7.5-1
Ubuntu:22.04:LTSflask-security4.0.0-1, 0

Timeline

  • Aug 2, 2022 CVE Published
  • Aug 3, 2022 EPSS Score
  • Sep 18, 2022 EPSS Score
  • Nov 4, 2022 EPSS Score
  • Feb 5, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 23, 2023 EPSS Score
  • May 8, 2023 EPSS Score
  • Aug 9, 2023 EPSS Score
  • Sep 25, 2023 EPSS Score
  • Nov 10, 2023 EPSS Score
  • Dec 27, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›