{ "dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": { "state": "PUBLISHED", "cveId": "CVE-2021-23385", "assignerOrgId": "bae035ff-b466-4ff4-94d0-fc9efd9e1730", "assignerShortName": "snyk", "dateUpdated": "2024-09-16T22:08:36.808Z", "dateReserved": "2021-01-08T00:00:00.000Z", "datePublished": "2022-08-02T13:25:14.717Z" }, "containers": { "cna": { "title": "Open Redirect", "datePublic": "2022-08-02T00:00:00.000Z", "providerMetadata": { "orgId": "bae035ff-b466-4ff4-94d0-fc9efd9e1730", "shortName": "snyk", "dateUpdated": "2023-08-28T18:06:09.073Z" }, "descriptions": [ { "lang": "en", "value": "This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\\\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False. **Note:** Flask-Security is not maintained anymore." } ], "affected": [ { "vendor": "n/a", "product": "Flask-Security", "versions": [ { "version": "0", "status": "affected", "lessThan": "unspecified", "versionType": "custom" } ] } ], "references": [ { "url": "https://security.snyk.io/vuln/SNYK-PYTHON-FLASKSECURITY-1293234" }, { "url": "https://github.com/mattupstate/flask-security" }, { "url": "https://snyk.io/blog/url-confusion-vulnerabilities/" }, { "name": "[debian-lts-announce] 20230828 [SECURITY] [DLA 3545-1] flask-security security update", "tags": [ "mailing-list" ], "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00034.html" } ], "credits": [ { "lang": "en", "value": "Noam Moshe of Claroty" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:P/RL:U/RC:C", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE", "exploitCodeMaturity": "PROOF_OF_CONCEPT", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "baseScore": 5.4, "temporalScore": 5.1, "baseSeverity": "MEDIUM", "temporalSeverity": "MEDIUM" } } ], "problemTypes": [ { "descriptions": [ { "type": "text", "lang": "en", "description": "Open Redirect" } ] } ] }, "adp": [ { "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-03T19:05:55.663Z" }, "title": "CVE Program Container", "references": [ { "url": "https://security.snyk.io/vuln/SNYK-PYTHON-FLASKSECURITY-1293234", "tags": [ "x_transferred" ] }, { "url": "https://github.com/mattupstate/flask-security", "tags": [ "x_transferred" ] }, { "url": "https://snyk.io/blog/url-confusion-vulnerabilities/", "tags": [ "x_transferred" ] }, { "name": "[debian-lts-announce] 20230828 [SECURITY] [DLA 3545-1] flask-security security update", "tags": [ "mailing-list", "x_transferred" ], "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00034.html" } ] } ] } }