CVE-2020-7965

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
29/01/2020
Last modified:
03/02/2020

Description

flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:webargs_project:webargs:*:*:*:*:*:*:*:* 5.0.0 (including) 5.5.2 (including)


References to Advisories, Solutions, and Tools