Vulnerabilities > CVE-2021-29621 - Information Exposure Through Discrepancy vulnerability in multiple products

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE

Summary

Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Upgrade to version 3.3.0 or higher to resolve.

Vulnerable Configurations

Part Description Count
Application
Flask-Appbuilder_Project
54
Application
Apache
1

Common Weakness Enumeration (CWE)