Lucene search

K
osvGoogleOSV:GHSA-XC3P-FF3M-F46V
HistoryMay 06, 2021 - 6:51 p.m.

Flask-Cors Directory Traversal vulnerability

2021-05-0618:51:48
Google
osv.dev
6

0.01 Low

EPSS

Percentile

83.6%

An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.