Flask-AppBuilder Observable Response Discrepancy
Low severity
GitHub Reviewed
Published
Mar 3, 2025
in
dpgaspar/Flask-AppBuilder
•
Updated Mar 3, 2025
Description
Published to the GitHub Advisory Database
Mar 3, 2025
Reviewed
Mar 3, 2025
Published by the National Vulnerability Database
Mar 3, 2025
Last updated
Mar 3, 2025
Impact
User enumeration in database authentication in Flask-AppBuilder <= 4.5.3 and werkzeug >= 3.0.0. Allows for a non authenticated user to enumerate existing usernames by timing the response time from the server when brute forcing requests to login.
Patches
Upgrade to flask-appbuilder>=4.5.3
Workarounds
Downgrade werkzeug to <3.0.0
References
Are there any links users can visit to find out more?
References