CVE-2024-6221: Improper Access Control in corydolphin/flask-cors
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the Access-Control-Allow-Private-Network CORS header to be set to true by default, without any configuration option. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
Other sources
A vulnerability in corydolphin/flask-cors version 4.0.1 allows the Access-Control-Allow-Private-Network CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to sensitive information, and potential network intrusions.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6221?
CVE-2024-6221 has a high severity level due to the risk of unauthorized access to private network resources.
How do I fix CVE-2024-6221?
To fix CVE-2024-6221, upgrade Flask-Cors to version 4.0.2 or later.
What systems are affected by CVE-2024-6221?
CVE-2024-6221 specifically affects Flask-Cors version 4.0.1.
What vulnerabilities does CVE-2024-6221 introduce?
CVE-2024-6221 introduces the risk of exposing private network resources due to a misconfigured CORS header.
What can happen if I do not address CVE-2024-6221?
If not addressed, CVE-2024-6221 can lead to unauthorized external access to sensitive network resources.