Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-29005


Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`, and setting an `AUTH_RATE_LIMIT`.


Published

2023-04-10T21:15:07.397

Last Modified

2025-03-07T14:37:51.330

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-307

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dpgaspar flask-appbuilder < 4.3.0 Yes

References