Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 03 Mar 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3. | |
Title | Observable Response Discrepancy in flask-appbuilder | |
Weaknesses | CWE-204 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-03T18:41:23.427Z
Reserved: 2025-01-16T17:31:06.459Z
Link: CVE-2025-24023

Updated: 2025-03-03T18:41:18.673Z

Status : Received
Published: 2025-03-03T16:15:41.820
Modified: 2025-03-03T16:15:41.820
Link: CVE-2025-24023

No data.