Observable Response Discrepancy in Flask-AppBuilder
Moderate severity
GitHub Reviewed
Published
Jan 31, 2022
in
dpgaspar/Flask-AppBuilder
•
Updated Sep 20, 2024
Description
Reviewed
Jan 31, 2022
Published by the National Vulnerability Database
Jan 31, 2022
Published to the GitHub Advisory Database
Feb 1, 2022
Last updated
Sep 20, 2024
Impact
User enumeration in database authentication in Flask-AppBuilder < 3.4.4. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in.
Patches
Upgrade to 3.4.4
Workarounds
References
For more information
If you have any questions or comments about this advisory:
References