• 公告ID (KylinSec-SA-2024-3738)

摘要:

A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.

安全等级: Low

公告ID: KylinSec-SA-2024-3738

发布日期: 2024年9月20日

关联CVE: CVE-2024-6221  

  • 详细介绍

1. 漏洞描述

   

A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2024-6221 KY3.4-5A python-Flask-Cors Unaffected
CVE-2024-6221 KY3.5.2 python-Flask-Cors Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2024-3737 下一篇:KylinSec-SA-2024-3739