• 公告ID (KylinSec-SA-2023-2355)

摘要:

python-flask security update

安全等级: High

公告ID: KylinSec-SA-2023-2355

发布日期: 2023年12月22日

关联CVE: CVE-2023-30861  

  • 详细介绍

1. 漏洞描述

   

Flask is a lightweight WSGI web application framework. It is designed to make getting started quick and easy, with the ability to scale up to complex applications. It began as a simple wrapper around Werkzeug and Jinja and has become one of the most popular Python web application frameworks.

Security Fix(es):

Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the proxy also caches `Set-Cookie` headers, it may send one client's `session` cookie to other clients. The severity depends on the application's use of the session and the proxy's behavior regarding cookies. The risk depends on all these conditions being met.

1. The application must be hosted behind a caching proxy that does not strip cookies or ignore responses with cookies.
2. The application sets `session.permanent = True`
3. The application does not access or modify the session at any point during a request.
4. `SESSION_REFRESH_EACH_REQUEST` enabled (the default).
5. The application does not set a `Cache-Control` header to indicate that a page is private or should not be cached.

This happens because vulnerable versions of Flask only set the `Vary: Cookie` header when the session is accessed or modified, not when it is refreshed (re-sent to update the expiration) without being accessed or modified. This issue has been fixed in versions 2.3.2 and 2.2.5.(CVE-2023-30861)

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2023-30861 KY3.4-5A python-flask Fixed

3. 影响组件

    python-flask

4. 修复版本

   

KY3.4-5A

软件名称 架构 版本号
python2-flask noarch 1.1.2-5.kb1.ky3_4
python3-flask noarch 1.1.2-5.kb1.ky3_4

5. 修复方法


方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm

方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名

6. 下载链接

   

KY3.4-5A:

x86_64:

     python2-flask   

     python3-flask   

aarch64:

     python2-flask   

     python3-flask   

上一篇:KylinSec-SA-2023-2354 下一篇:KylinSec-SA-2023-1900