icon

We found results for “

CVE-2024-45314

Good to know:

icon
icon

Date: September 4, 2024

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for "/login" per the directions provided in the GitHub Security Advisory.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Use of Web Browser Cache Containing Sensitive Information

CWE-525

Top Fix

icon

Upgrade Version

Upgrade to version flask-appbuilder - 4.5.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us