CVE-2024-6866

NameCVE-2024-6866
Descriptioncorydolphin/flask-cors version 4.01 contains a vulnerability where the ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4197-1
Debian Bugs1100988

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python-flask-cors (PTS)bullseye3.0.9-2vulnerable
bullseye (security)3.0.9-2+deb11u1fixed
bookworm3.0.10-2+deb12u1fixed
forky, sid, trixie6.0.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python-flask-corssourcebullseye3.0.9-2+deb11u1DLA-4197-1
python-flask-corssourcebookworm3.0.10-2+deb12u1
python-flask-corssource(unstable)6.0.0-11100988

Notes

https://huntr.com/bounties/808c11af-faee-43a8-824b-b5ab4f62b9e6
https://github.com/advisories/GHSA-43qf-4rqw-9q2g
Fixed by: https://github.com/corydolphin/flask-cors/commit/eb39516a3c96b90d0ae5f51293972395ec3ef358 (6.0.0)

Search for package or bug name: Reporting problems