Cross-site request forgery in Flask-Security - CVE-2021-21241
Published: September 6, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website and obtain authentication token.
Affected software
Arch Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
python3-Flask-Security-Too
python-flask-security-too
How to mitigate CVE-2021-21241
python3-Flask-Security-Too - update to 3.4.2-150200.3.3.1
python-flask-security-too - update to 4.0.1-1
External References
- https://github.com/Flask-Middleware/flask-security/commit/61d313150b5f620d0b800896c4f2199005e84b1f
- https://github.com/Flask-Middleware/flask-security/commit/6d50ee9169acf813257c37b75babe9c28e83542a
- https://github.com/Flask-Middleware/flask-security/pull/422
- https://github.com/Flask-Middleware/flask-security/releases/tag/3.4.5
- https://github.com/Flask-Middleware/flask-security/security/advisories/GHSA-hh7m-rx4f-4vpv