flask-security-too
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting flask-security-toopage 1 of 1
- CVE-2021-21241HIGHCVSS 7.4EG 7.4✓ Fixed in 3.4.52021-01-11
vulnerable: 3.3.0 ... 3.4.4 (9 versions)
The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. In Flask-Security-Too fr…
- CVE-2021-32618LOWCVSS 3.1EG 3.1✓ Fixed in 4.1.02021-05-17
vulnerable: 3.0.1 ... 4.0.1 (27 versions)
The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions of Flask-S…
- CVE-2023-49438MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.3.32023-12-26
vulnerable: 3.0.1 ... 5.3.2 (44 versions)
An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes.
Check whether flask-security-too is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for flask-security-too CVEs against the assets you own.
Start Free Scan →