Skip to content

Commit 401ed44

Browse files
committed
1 parent ed3feb6 commit 401ed44

File tree

1 file changed

+1
-5
lines changed

1 file changed

+1
-5
lines changed

advisories/github-reviewed/2024/08/GHSA-hxwh-jpp2-84pm/GHSA-hxwh-jpp2-84pm.json

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,18 +1,14 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-hxwh-jpp2-84pm",
4-
"modified": "2025-04-07T19:51:43Z",
4+
"modified": "2025-04-07T19:51:44Z",
55
"published": "2024-08-18T21:31:07Z",
66
"aliases": [
77
"CVE-2024-6221"
88
],
99
"summary": "Flask-CORS allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default",
1010
"details": "A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.",
1111
"severity": [
12-
{
13-
"type": "CVSS_V3",
14-
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
15-
},
1612
{
1713
"type": "CVSS_V4",
1814
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"

0 commit comments

Comments
 (0)