Lucene search

K
osvGoogleOSV:PYSEC-2021-341
HistoryAug 16, 2021 - 6:15 p.m.

PYSEC-2021-341

2021-08-1618:15:00
Google
osv.dev
16
access control
lin-cms-flask
remote attackers
sensitive information
privileges
authentication token
logout
packet replay

EPSS

0.005

Percentile

76.9%

Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user’s authentication token upon logout, which allows for replaying packets.

EPSS

0.005

Percentile

76.9%

Related for OSV:PYSEC-2021-341