PT-2021-14351 · Pypi+1 · Flask-Security-Too+1

CVE-2021-21241

·

Published

2021-01-11

·

Updated

2024-12-06

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Flask-Security-Too versions 3.3.0 through 3.4.5
Description: The issue concerns the Flask-Security-Too package, which is used to add security features to Flask applications. In affected versions, the /login and /change endpoints can return the authenticated user's authentication token in response to a GET request. Since GET requests are not protected with a CSRF token, this could allow a malicious third-party site to acquire the authentication token.
Recommendations: For versions 3.3.0 through 3.4.5, update to version 3.4.5 or 4.0.0 to resolve the issue. As a temporary workaround, if authentication tokens are not being used, set the SECURITY TOKEN MAX AGE to "0" (seconds) to make the token unusable.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21241
GHSA-HH7M-RX4F-4VPV
OPENSUSE-SU-2022_3093-1
OPENSUSE-SU-2024:13561-1
OPENSUSE-SU-2024:14555-1
PYSEC-2021-91
SUSE-SU-2022:3093-1
SUSE-SU-2022_3093-1

Affected Products

Flask-Security-Too
Suse