Input validation error in Flask - CVE-2019-1010083
Published: July 19, 2019
Vulnerability identifier: #VU19269
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1010083
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the package allows for unsafe encoded JSON data to be decoded. A remote attacker can perform a denial of service attack on the affected system.
Affected software
Flask
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
F5OS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
BIG-IQ Centralized Management
python3-Flask
python-Flask
QRadar Assistant
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
F5OS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
BIG-IQ Centralized Management
python3-Flask
python-Flask
QRadar Assistant
How to mitigate CVE-2019-1010083
Install updates from vendor's website.
Flask - update to 1.0
python3-Flask - update to 0.12.1-7.7.1
python-Flask - update to 0.12.1-7.7.1
QRadar Assistant - update to 3.7.0
python3-Flask - update to 0.12.1-7.7.1
python-Flask - update to 0.12.1-7.7.1
QRadar Assistant - update to 3.7.0