Skip to main content

Vendor/product archive

corydolphin / flask-cors CVEs

Beta · best-effort

2 CVEs tagged to corydolphin / flask-cors0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-6221

Published Aug 18, 2024

A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose privat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1681

Published Apr 19, 2024

corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1