Sensitive Data Exposure in Flask-AppBuilder by DPGaspar
CVE-2024-45314

5.5MEDIUM

Key Information:

Vendor

Dpgaspar

Vendor
CVE Published:
4 September 2024

What is CVE-2024-45314?

Flask-AppBuilder, an application development framework, exhibits a vulnerability related to the default cache directives of the authentication database login form. Before version 4.5.1, this flaw allows browsers to locally cache sensitive data, posing risks particularly in shared environments. Users are advised to upgrade to version 4.5.1 or implement specific HTTP headers for the /login endpoint to mitigate this risk, as detailed in the GitHub Security Advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.