CVE-2023-30861
Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
02/05/2023
Última modificación:
20/08/2023
Descripción
*** Pendiente de traducción *** Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the proxy also caches `Set-Cookie` headers, it may send one client&#39;s `session` cookie to other clients. The severity depends on the application&#39;s use of the session and the proxy&#39;s behavior regarding cookies. The risk depends on all these conditions being met.<br />
<br />
1. The application must be hosted behind a caching proxy that does not strip cookies or ignore responses with cookies.<br />
2. The application sets `session.permanent = True`<br />
3. The application does not access or modify the session at any point during a request.<br />
4. `SESSION_REFRESH_EACH_REQUEST` enabled (the default).<br />
5. The application does not set a `Cache-Control` header to indicate that a page is private or should not be cached.<br />
<br />
This happens because vulnerable versions of Flask only set the `Vary: Cookie` header when the session is accessed or modified, not when it is refreshed (re-sent to update the expiration) without being accessed or modified. This issue has been fixed in versions 2.3.2 and 2.2.5.
Impacto
Puntuación base 3.x
7.50
Gravedad 3.x
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:palletsprojects:flask:*:*:*:*:*:*:*:* | 2.2.5 (excluyendo) | |
| cpe:2.3:a:palletsprojects:flask:*:*:*:*:*:*:*:* | 2.3.0 (incluyendo) | 2.3.2 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://github.com/pallets/flask/commit/70f906c51ce49c485f1d355703e9cc3386b1cc2b
- https://github.com/pallets/flask/commit/afd63b16170b7c047f5758eb910c416511e9c965
- https://github.com/pallets/flask/releases/tag/2.2.5
- https://github.com/pallets/flask/releases/tag/2.3.2
- https://github.com/pallets/flask/security/advisories/GHSA-m2qf-hxjv-5gpq
- https://lists.debian.org/debian-lts-announce/2023/08/msg00024.html
- https://security.netapp.com/advisory/ntap-20230818-0006/
- https://www.debian.org/security/2023/dsa-5442



