Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26540
HistorySep 01, 2020 - 2:56 a.m.

Directory Traversal

2020-09-0102:56:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.01 Low

EPSS

Percentile

83.6%

flask_cors is vulnerable to directory traversal. The vulnerability exists as it does not sufficiently handle the pathnames for CORS resource matching before evaluating resource rules, allowing an attacker to submit a malicious pathname containing the ../ characters and access arbitrary system files.

CPENameOperatorVersion
flask-corsle3.0.8
flask-corsle3.0.8