USN-6019-1: Flask-CORS vulnerability

Publication date

13 April 2023

Overview

Applications using Flask-CORS could be made to expose sensitive information.

Releases


Packages

  • python-flask-cors - Flask extension for handling Cross Origin Resource Sharing (CORS)

Details

It was discovered that Flask-CORS did not properly escape paths before
evaluating resource rules. An attacker could possibly use this to
expose sensitive information.

It was discovered that Flask-CORS did not properly escape paths before
evaluating resource rules. An attacker could possibly use this to
expose sensitive information.

Update instructions

After a standard system update you need to restart application using Flask-CORS to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
20.04 focal python3-flask-cors –  3.0.8-2ubuntu0.1

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›