A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions. | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions. |
| References |
|
Tue, 20 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other | |
| Metrics |
cvssV3_1
|
Mon, 19 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Corydolphin
Corydolphin flask-cors |
|
| CPEs | cpe:2.3:a:corydolphin:flask-cors:4.0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Corydolphin
Corydolphin flask-cors |
|
| Metrics |
ssvc
|
Sun, 18 Aug 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions. | |
| Title | Improper Access Control in corydolphin/flask-cors | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published: 2024-08-18T18:58:20.551Z
Updated: 2025-04-07T15:03:37.262Z
Reserved: 2024-06-20T18:32:12.417Z
Link: CVE-2024-6221
Updated: 2024-08-19T13:48:08.219Z
Status : Modified
Published: 2024-08-18T19:15:04.730
Modified: 2025-04-07T15:15:42.060
Link: CVE-2024-6221
No data.