CVE-2024-6839
Last modified
CVE-2024-6839 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to less restrictive CORS policies being applied to sensitive endpoints. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to less restrictive CORS policies being applied to sensitive endpoints. This mismatch in regex pattern priority allows unauthorized cross-origin access to sensitive data or functionality, potentially exposing confidential information and increasing the risk of unauthorized actions by malicious actors.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Flask-Cors Project | Flask-Cors | 4.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-6839?
How severe is CVE-2024-6839?
How do I fix CVE-2024-6839?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-6832The account locking mechanism fails to trigger when secondar…7.5
- CVE-2024-6833A vulnerability in Zowe CLI allows local, privileged actors …5.9
- CVE-2024-6834A vulnerability in APIML Spring Cloud Gateway which leverage…9
- CVE-2024-6835The Ivory Search – WordPress Search Plugin plugin for WordPr…5.3
- CVE-2024-6836The Funnel Builder for WordPress by FunnelKit – Customize Wo…4.3
- CVE-2024-6838In mlflow/mlflow version v2.13.2, a vulnerability exists tha…5.3
- CVE-2024-6840An improper authorization flaw exists in the Ansible Automat…6.6
- CVE-2024-6841A Cross-Site Request Forgery (CSRF) vulnerability exists in …6.5
- CVE-2024-6842In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-…7.5
- CVE-2024-6843The Chatbot with ChatGPT WordPress plugin before 2.4.5 does …6.1
- CVE-2024-6844A vulnerability in corydolphin/flask-cors version 4.0.1 allo…5.3
- CVE-2024-6845The Chatbot with ChatGPT WordPress plugin before 2.4.6 does …5.3
Are you affected by CVE-2024-6839?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
