Information disclosure in Flask - CVE-2023-30861

 

Information disclosure in Flask - CVE-2023-30861

Published: May 2, 2023 / Updated: May 2, 2023


Vulnerability identifier: #VU75664
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30861
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to missing Vary: Cookie header. A remote attacker can gain unauthorized access to sensitive information on the system.


Affected software

Flask
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
Fedora
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Oracle Enterprise Operations Monitor
watsonx.data
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
Cloud Pak for Data
Oracle Business Intelligence Enterprise Edition
Storage Defender – Data Protect
Cloud Pak for Data System 2.0
QRadar Assistant
IBM Cloud Pak for Watson AIOps
watsonx Code Assistant for Ansible
IBM QRadar Incident Forensics
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Automated Test Suite
IBM Cloud Pak for Data System
IBM Process Mining
Spectrum Discover
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite
IBM Spectrum Protect Plus
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Security Edge Protection Proxy
python-flask-doc
python-flask
python-flask (Red Hat package)
python3-flask
python3-Flask
python2-Flask
python3-Flask-doc
python3-flask (Ubuntu package)
flask (Debian package)
python2-flask
cri-o (Red Hat package)
NetworkManager (Red Hat package)
conmon (Red Hat package)
podman (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
Quay
IBM Storage Scale System

How to mitigate CVE-2023-30861

Install updates from vendor's website.

Flask - addressed in versions 2.2.5, 2.3.2
IBM Cloud Pak for Multicloud Management - update to 2.3.8
watsonx.data - update to 2.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.21, 4.13.3
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
python-flask-doc - addressed in versions 0.10.1-7, 0.12.2-5
python-flask - update to 0.10.1-7
python-flask (Red Hat package) - addressed in versions 0.10.1-7.el7_9, 1.0.2-8.el8ost, 1.1.2-6.el9ost, 2.0.1-3.el9
python3-flask - update to 0.12.2-5
python3-Flask - addressed in versions 1.0.2-150100.6.3.1, 1.0.4-150400.3.3.1
python2-Flask - update to 1.0.2-150100.6.3.1
python3-Flask-doc - update to 1.0.4-150400.3.3.1
IBM Cloud Pak for Data System - update to 1.0.9.0
python3-flask (Ubuntu package) - addressed in versions 1.1.1-2ubuntu0.1, 2.0.1-2ubuntu1.1, 2.0.3-1ubuntu1.1, 2.2.2-2ubuntu1.1
flask (Debian package) - update to 1.1.2-2+deb11u1
python-flask - update to 1.1.2-5
python3-flask - update to 1.1.2-5
python-flask - update to 1.1.2-5
python2-flask - update to 1.1.2-5
python3-flask - update to 1.1.4-1.el7
Storage Defender – Data Protect - update to 1.3.0
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Process Mining - update to 1.14.1
cri-o (Red Hat package) - addressed in versions 1.26.3-8.rhaos4.13.git9232b13.el8, 1.26.3-9.rhaos4.13.git9232b13.el9
NetworkManager (Red Hat package) - update to 1.42.2-2.el9_2
Cloud Pak for Data System 2.0 - update to 2.0.2.1.IF2
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
conmon (Red Hat package) - update to 2.1.7-1.1.rhaos4.13.el9
python-flask - update to 2.2.5-1.fc39
QRadar Assistant - update to 3.7.0
Quay - update to 3.10.0
IBM Cloud Pak for Watson AIOps - update to 4.1
podman (Red Hat package) - update to 4.2.0-4.1.rhaos4.12.el8
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
Cloud Pak for Data - update to 4.8.5
openshift-ansible (Red Hat package) - addressed in versions 4.13.0-202305301841.p0.g148be47.assembly.stream.el8, 4.13.0-202305301841.p0.g148be47.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.13.0-202305312300.p0.g05d83ef.assembly.stream.el8, 4.13.0-202305312300.p0.g05d83ef.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.13.0-202305312300.p0.g7a891f0.assembly.stream.el8, 4.13.0-202305312300.p0.g7a891f0.assembly.stream.el9
watsonx Code Assistant for Ansible - update to 5.0.3
IBM Storage Scale System - update to 6.1.8.1
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Maximo Application Suite - addressed in versions 8.8.9, 8.9.5, 8.10.1
IBM Spectrum Protect Plus - update to 10.1.15

External References

Related Security Bulletins