USN-6019-1: Flask-CORS vulnerability
Publication date
13 April 2023
Overview
Applications using Flask-CORS could be made to expose sensitive information.
Releases
Packages
- python-flask-cors - Flask extension for handling Cross Origin Resource Sharing (CORS)
Details
It was discovered that Flask-CORS did not properly escape paths before
evaluating resource rules. An attacker could possibly use this to
expose sensitive information.
It was discovered that Flask-CORS did not properly escape paths before
evaluating resource rules. An attacker could possibly use this to
expose sensitive information.
Update instructions
After a standard system update you need to restart application using Flask-CORS to make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
20.04 focal | python3-flask-cors – 3.0.8-2ubuntu0.1 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.