CVE-2024-6221
Published Aug 18, 2024A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose privat…
Vendor/product archive
2 CVEs tagged to corydolphin / flask-cors — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose privat…
corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted…