Observable Response Discrepancy in Flask-AppBuilder
Moderate severity
GitHub Reviewed
Published
Jan 31, 2022
in
dpgaspar/Flask-AppBuilder
•
Updated Mar 7, 2025
Description
Reviewed
Jan 31, 2022
Published by the National Vulnerability Database
Jan 31, 2022
Published to the GitHub Advisory Database
Feb 1, 2022
Last updated
Mar 7, 2025
Impact
User enumeration in database authentication in Flask-AppBuilder < 3.4.4. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in.
Patches
Upgrade to 3.4.4
Workarounds
References
For more information
If you have any questions or comments about this advisory:
References