flask-appbuilder
PyPI14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting flask-appbuilderpage 1 of 1
- CVE-2021-29621MEDIUMCVSS 5.3EG 5.3fixed in 3.3.02021-06-07
vulnerable: 0.1.10 ... 3.3.0rc1 (238 versions)
Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time fr…
- CVE-2021-32805HIGHCVSS 7.2EG 7.2fixed in 3.3.22021-09-08
vulnerable: 0.1.10 ... 3.3.2rc1 (242 versions)
Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-AppBuilder OAuth, an attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-…
- CVE-2021-41265HIGHCVSS 8.1EG 8.1fixed in 3.3.42021-12-09
vulnerable: 0.1.10 ... 3.3.4rc1 (246 versions)
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successf…
- CVE-2022-21659MEDIUMCVSS 5.3EG 5.3fixed in 3.4.4 or 3.4.2, by version range2022-01-31
vulnerable: 0.1.10 ... 3.4.2rc1 (255 versions)
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate exis…
- CVE-2022-24776MEDIUMCVSS 6.1EG 6.1fixed in 3.4.52022-03-24
vulnerable: 0.1.10 ... 3.4.5rc1 (262 versions)
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue i…
- CVE-2022-31177LOWCVSS 2.7EG 2.7fixed in 4.1.32022-08-01
vulnerable: 0.1.10 ... 4.1.3rc1 (274 versions)
Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These filters cou…
- CVE-2023-29005HIGHCVSS 7.5EG 7.5fixed in 4.3.02023-04-10
vulnerable: 0.1.10 ... 4.3.0rc1 (288 versions)
Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`,…
- CVE-2023-34110LOWCVSS 2.7EG 2.7fixed in 4.3.22023-06-22
vulnerable: 0.1.10 ... 4.3.2rc2 (293 versions)
Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a special character on the add, edit User forms trigger a data…
- CVE-2024-25128CRITICALCVSS 9.1EG 9.1fixed in 4.3.112024-02-29
vulnerable: 0.1.10 ... 4.3.9rc1 (313 versions)
Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested Op…
- CVE-2024-27083MEDIUMCVSS 4.3EG 4.3fixed in 4.2.12024-02-29
vulnerable: 4.1.4 ... 4.2.1rc1 (9 versions)
Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to th…
- CVE-2024-45314LOWCVSS 3.6EG 3.6fixed in 4.5.12024-09-04
vulnerable: 0.1.10 ... 4.5.1rc1 (321 versions)
Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer re…
- CVE-2025-24023LOWCVSS 3.7EG 3.7fixed in 4.5.32025-03-03
vulnerable: 0.1.10 ... 4.5.3rc1 (325 versions)
Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This …
- CVE-2025-32962MEDIUMCVSS 4.3EG 4.3fixed in 4.6.22025-05-16
vulnerable: 0.1.10 ... 4.6.2rc1 (341 versions)
Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-A…
- CVE-2025-58065MEDIUMCVSS 6.5EG 6.5fixed in 4.8.12025-09-11
vulnerable: 0.1.10 ... 4.8.1rc1 (353 versions)
Flask-AppBuilder is an application development framework. Prior to version 4.8.1, when Flask-AppBuilder is configured to use OAuth, LDAP, or other non-database authentication methods, the password reset endpoint remains registered and acce…
Check whether flask-appbuilder is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for flask-appbuilder CVEs against the assets you own.
Book a Demo →