製品・ソフトウェアに関する情報
dpgaspar の flask app builder における脆弱性
Title dpgaspar の flask app builder における脆弱性
Summary

dpgaspar の flask app builder には、不特定の脆弱性が存在します。

Possible impacts 情報を取得される、および情報を改ざんされる可能性があります。
Solution

ベンダアドバイザリまたはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。

Publication Date Feb. 29, 2024, midnight
Registration Date Oct. 16, 2025, 3:52 p.m.
Last Update Oct. 16, 2025, 3:52 p.m.
CVSS3.0 : 緊急
Score 9.1
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected System
dpgaspar
flask app builder 4.3.11 未満
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
その他
Change Log
No Changed Details Date of change
1 [2025年10月16日]
  掲載
Oct. 16, 2025, 3:52 p.m.

NVD Vulnerability Information
CVE-2024-25128
Summary

Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.

Publication Date Feb. 29, 2024, 10:44 a.m.
Registration Date Feb. 29, 2024, 4 p.m.
Last Update Nov. 21, 2024, 6 p.m.
Related information, measures and tools
Common Vulnerabilities List