Lucene search

K
osvGoogleOSV:GHSA-4298-89HC-6RFV
HistoryAug 09, 2021 - 8:44 p.m.

Open Redirect in Flask-User

2021-08-0920:44:32
Google
osv.dev
7

0.001 Low

EPSS

Percentile

43.8%

This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple backslashes such as /////evil.com/path or \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using autocorrect_location_header=False.

0.001 Low

EPSS

Percentile

43.8%