Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40395
HistoryMay 04, 2023 - 3:01 a.m.

Information Disclosure

2023-05-0403:01:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
flask
information disclosure
vary cookie header
save_session function
sessions.py

0.002 Low

EPSS

Percentile

57.1%

flask is vulnerable to Information Disclosure. The vulnerability exists due to the missing Vary cookie header in the save_session function of sessions.py, which leads to the disclosure of the session cookie, or sending data to a client who did not make the request.