Input validation error in Flask - CVE-2019-1010083

 

Input validation error in Flask - CVE-2019-1010083

Published: July 19, 2019


Vulnerability identifier: #VU19269
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1010083
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the package allows for unsafe encoded JSON data to be decoded. A remote attacker can perform a denial of service attack on the affected system.


Affected software

Flask
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
F5OS
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
BIG-IQ Centralized Management
python3-Flask
python-Flask
QRadar Assistant

How to mitigate CVE-2019-1010083

Install updates from vendor's website.

Flask - update to 1.0
python3-Flask - update to 0.12.1-7.7.1
python-Flask - update to 0.12.1-7.7.1
QRadar Assistant - update to 3.7.0

External References

Related Security Bulletins