Lucene search

K
osvGoogleOSV:CVE-2020-25032
HistoryAug 31, 2020 - 4:15 a.m.

CVE-2020-25032

2020-08-3104:15:12
Google
osv.dev
5

6.6 Medium

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.6%

An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows …/ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

6.6 Medium

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.6%