Information disclosure in Flask - CVE-2023-30861
Published: May 2, 2023 / Updated: May 2, 2023
Vulnerability identifier: #VU75664
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30861
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to missing Vary: Cookie header. A remote attacker can gain unauthorized access to sensitive information on the system.
Affected software
Flask
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
Fedora
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Oracle Enterprise Operations Monitor
watsonx.data
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
Cloud Pak for Data
Oracle Business Intelligence Enterprise Edition
Storage Defender – Data Protect
Cloud Pak for Data System 2.0
QRadar Assistant
IBM Cloud Pak for Watson AIOps
watsonx Code Assistant for Ansible
IBM QRadar Incident Forensics
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Automated Test Suite
IBM Cloud Pak for Data System
IBM Process Mining
Spectrum Discover
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite
IBM Spectrum Protect Plus
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Security Edge Protection Proxy
python-flask-doc
python-flask
python-flask (Red Hat package)
python3-flask
python3-Flask
python2-Flask
python3-Flask-doc
python3-flask (Ubuntu package)
flask (Debian package)
python2-flask
cri-o (Red Hat package)
NetworkManager (Red Hat package)
conmon (Red Hat package)
podman (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
Quay
IBM Storage Scale System
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
Fedora
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
SUSE Enterprise Storage
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Ubuntu
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Oracle Enterprise Operations Monitor
watsonx.data
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
Cloud Pak for Data
Oracle Business Intelligence Enterprise Edition
Storage Defender – Data Protect
Cloud Pak for Data System 2.0
QRadar Assistant
IBM Cloud Pak for Watson AIOps
watsonx Code Assistant for Ansible
IBM QRadar Incident Forensics
Red Hat OpenStack
Red Hat OpenStack for IBM Power
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Automated Test Suite
IBM Cloud Pak for Data System
IBM Process Mining
Spectrum Discover
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Maximo Application Suite
IBM Spectrum Protect Plus
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Oracle Communications Cloud Native Core Security Edge Protection Proxy
python-flask-doc
python-flask
python-flask (Red Hat package)
python3-flask
python3-Flask
python2-Flask
python3-Flask-doc
python3-flask (Ubuntu package)
flask (Debian package)
python2-flask
cri-o (Red Hat package)
NetworkManager (Red Hat package)
conmon (Red Hat package)
podman (Red Hat package)
openshift-ansible (Red Hat package)
openshift-clients (Red Hat package)
openshift (Red Hat package)
Quay
IBM Storage Scale System
How to mitigate CVE-2023-30861
Install updates from vendor's website.
Flask - addressed in versions 2.2.5, 2.3.2
IBM Cloud Pak for Multicloud Management - update to 2.3.8
watsonx.data - update to 2.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.21, 4.13.3
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
python-flask-doc - addressed in versions 0.10.1-7, 0.12.2-5
python-flask - update to 0.10.1-7
python-flask (Red Hat package) - addressed in versions 0.10.1-7.el7_9, 1.0.2-8.el8ost, 1.1.2-6.el9ost, 2.0.1-3.el9
python3-flask - update to 0.12.2-5
python3-Flask - addressed in versions 1.0.2-150100.6.3.1, 1.0.4-150400.3.3.1
python2-Flask - update to 1.0.2-150100.6.3.1
python3-Flask-doc - update to 1.0.4-150400.3.3.1
IBM Cloud Pak for Data System - update to 1.0.9.0
python3-flask (Ubuntu package) - addressed in versions 1.1.1-2ubuntu0.1, 2.0.1-2ubuntu1.1, 2.0.3-1ubuntu1.1, 2.2.2-2ubuntu1.1
flask (Debian package) - update to 1.1.2-2+deb11u1
python-flask - update to 1.1.2-5
python3-flask - update to 1.1.2-5
python-flask - update to 1.1.2-5
python2-flask - update to 1.1.2-5
python3-flask - update to 1.1.4-1.el7
Storage Defender – Data Protect - update to 1.3.0
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Process Mining - update to 1.14.1
cri-o (Red Hat package) - addressed in versions 1.26.3-8.rhaos4.13.git9232b13.el8, 1.26.3-9.rhaos4.13.git9232b13.el9
NetworkManager (Red Hat package) - update to 1.42.2-2.el9_2
Cloud Pak for Data System 2.0 - update to 2.0.2.1.IF2
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
conmon (Red Hat package) - update to 2.1.7-1.1.rhaos4.13.el9
python-flask - update to 2.2.5-1.fc39
QRadar Assistant - update to 3.7.0
Quay - update to 3.10.0
IBM Cloud Pak for Watson AIOps - update to 4.1
podman (Red Hat package) - update to 4.2.0-4.1.rhaos4.12.el8
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
Cloud Pak for Data - update to 4.8.5
openshift-ansible (Red Hat package) - addressed in versions 4.13.0-202305301841.p0.g148be47.assembly.stream.el8, 4.13.0-202305301841.p0.g148be47.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.13.0-202305312300.p0.g05d83ef.assembly.stream.el8, 4.13.0-202305312300.p0.g05d83ef.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.13.0-202305312300.p0.g7a891f0.assembly.stream.el8, 4.13.0-202305312300.p0.g7a891f0.assembly.stream.el9
watsonx Code Assistant for Ansible - update to 5.0.3
IBM Storage Scale System - update to 6.1.8.1
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Maximo Application Suite - addressed in versions 8.8.9, 8.9.5, 8.10.1
IBM Spectrum Protect Plus - update to 10.1.15
IBM Cloud Pak for Multicloud Management - update to 2.3.8
watsonx.data - update to 2.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.21, 4.13.3
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
python-flask-doc - addressed in versions 0.10.1-7, 0.12.2-5
python-flask - update to 0.10.1-7
python-flask (Red Hat package) - addressed in versions 0.10.1-7.el7_9, 1.0.2-8.el8ost, 1.1.2-6.el9ost, 2.0.1-3.el9
python3-flask - update to 0.12.2-5
python3-Flask - addressed in versions 1.0.2-150100.6.3.1, 1.0.4-150400.3.3.1
python2-Flask - update to 1.0.2-150100.6.3.1
python3-Flask-doc - update to 1.0.4-150400.3.3.1
IBM Cloud Pak for Data System - update to 1.0.9.0
python3-flask (Ubuntu package) - addressed in versions 1.1.1-2ubuntu0.1, 2.0.1-2ubuntu1.1, 2.0.3-1ubuntu1.1, 2.2.2-2ubuntu1.1
flask (Debian package) - update to 1.1.2-2+deb11u1
python-flask - update to 1.1.2-5
python3-flask - update to 1.1.2-5
python-flask - update to 1.1.2-5
python2-flask - update to 1.1.2-5
python3-flask - update to 1.1.4-1.el7
Storage Defender – Data Protect - update to 1.3.0
Cloud Pak for Security (CP4S) - update to 1.10.12.0
IBM Process Mining - update to 1.14.1
cri-o (Red Hat package) - addressed in versions 1.26.3-8.rhaos4.13.git9232b13.el8, 1.26.3-9.rhaos4.13.git9232b13.el9
NetworkManager (Red Hat package) - update to 1.42.2-2.el9_2
Cloud Pak for Data System 2.0 - update to 2.0.2.1.IF2
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
conmon (Red Hat package) - update to 2.1.7-1.1.rhaos4.13.el9
python-flask - update to 2.2.5-1.fc39
QRadar Assistant - update to 3.7.0
Quay - update to 3.10.0
IBM Cloud Pak for Watson AIOps - update to 4.1
podman (Red Hat package) - update to 4.2.0-4.1.rhaos4.12.el8
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.7.0
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.7
Cloud Pak for Data - update to 4.8.5
openshift-ansible (Red Hat package) - addressed in versions 4.13.0-202305301841.p0.g148be47.assembly.stream.el8, 4.13.0-202305301841.p0.g148be47.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.13.0-202305312300.p0.g05d83ef.assembly.stream.el8, 4.13.0-202305312300.p0.g05d83ef.assembly.stream.el9
openshift (Red Hat package) - addressed in versions 4.13.0-202305312300.p0.g7a891f0.assembly.stream.el8, 4.13.0-202305312300.p0.g7a891f0.assembly.stream.el9
watsonx Code Assistant for Ansible - update to 5.0.3
IBM Storage Scale System - update to 6.1.8.1
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Maximo Application Suite - addressed in versions 8.8.9, 8.9.5, 8.10.1
IBM Spectrum Protect Plus - update to 10.1.15
External References
Related Security Bulletins
- Information disclosure in Flask
- SUSE update for python-Flask
- SUSE update for python-Flask
- Ubuntu update for flask
- Red Hat OpenStack Platform 16.1 update for Flask
- Red Hat OpenStack Platform 16.2 update for Flask
- Red Hat OpenStack Platform 17.0 update for Flask
- Information disclosure in IBM Maximo Application Suite
- Red Hat Enterprise Linux 7 Extras update for python-flask
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- OpenShift Container Platform 4.13 update for flask
- Multiple vulnerabilities in IBM Spectrum Protect Plus File Systems Agent
- Multiple vulnerabilities in IBM Spectrum Discover
- Debian update for flask
- IBM Process Mining update for Flask
- Information disclosure in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Automated Test Suite
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Security Edge Protection Proxy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Binding Support Function
- SUSE update for python-Flask
- Multiple vulnerabilities in IBM Watson Knowledge Catalog for IBM Cloud Pak for Data
- Information disclosure in IBM Elastic Storage System
- Fedora 39 update for python-flask
- Fedora EPEL 7 update for python3-flask
- Multiple vulnerabilities in IBM Storage Defender Data Protect
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Oracle Enterprise Operations Monitor
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- openEuler update for python-flask
- openEuler 20.03 LTS SP4 update for python-flask
- Multiple vulnerabilities in IBM QRadar Assistant
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics
- IBM watsonx Code Assistant for Ansible update for Pallets Flask
- Amazon Linux AMI update for python-flask
- IBM Cloud Pak for Data System 2.0 update for Pallets Flask
- Anolis OS update for python-flask
- Anolis OS update for python-flask
- IBM Cloud Pak for Data System update for Pallets Flask
- Dell RecoverPoint for Virtual Machines update for third-party components
- IBM Cloud Pak for Data update for Pallets Flask
- IBM watsonx.data update for Flask