USN-6792-1: Flask-Security vulnerability
28 May 2024
Flask-Security could be made to bypass URL validation and redirect to arbitary URL.
Releases
Packages
- flask-security - Simple security for Flask apps (Python 3)
Details
Naom Moshe discovered that Flask-Security incorrectly validated URLs. An attacker could use this issue to redirect users to arbitrary URLs.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
-
python3-flask-security
-
1.7.5-2ubuntu0.18.04.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.