PyPI: flask-appbuilder
CVE-2023-29005
Safety vulnerability ID: SFTY-20230410-56615
Safety legacy ID: pyup.io-54971
Flask-AppBuilder 4.3.0 includes a fix for CVE-2023-29005: Versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using 'AUTH_RATE_LIMITED = True', 'RATELIMIT_ENABLED = True', and setting an 'AUTH_RATE_LIMIT'. https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-9hcr-9hcv-x6pv
Overview
Flask-AppBuilder Has No Rate Limiting on Login AUTH DB
Advisory
Flask-AppBuilder 4.3.0 includes a fix for CVE-2023-29005: Versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using 'AUTH_RATE_LIMITED = True', 'RATELIMIT_ENABLED = True', and setting an 'AUTH_RATE_LIMIT'. https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-9hcr-9hcv-x6pv
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20230410-56615/CVE-2023-29005
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29005
- https://flask-limiter.readthedocs.io/en/stable/configuration.html
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-9hcr-9hcv-x6pv
- https://github.com/dpgaspar/Flask-AppBuilder/security/advisories/GHSA-9hcr-9hcv-x6pv
- https://github.com/dpgaspar/Flask-AppBuilder/pull/1976
- https://flask-limiter.readthedocs.io/en/stable/configuration.html
- https://github.com/dpgaspar/Flask-AppBuilder/releases/tag/v4.3.0
- https://nvd.nist.gov/vuln/detail/CVE-2023-29005
- https://github.com/advisories/GHSA-9hcr-9hcv-x6pv
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
