CVE-2022-24776

MEDIUM

Flask-AppBuilder < 3.4.5 - Open Redirect via Database Authentication Login Page

Title source: llm
STIX 2.1

Description

Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are currently no known workarounds.

References (3)

Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/dpgaspar/Flask-AppBuilder/pull/1804
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/dpgaspar/Flask-AppBuilder/releases/tag/v3.4.5

Scores

CVSS v3 6.1
EPSS 0.0092
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
dpgaspar/flask-appbuilder < 3.4.5
pypi/Flask-AppBuilder 0 - 3.4.5PyPI
Published Mar 24, 2022
Tracked Since Feb 18, 2026