MGASA-2025-0286

Source
https://advisories.mageia.org/MGASA-2025-0286.html
Import Source
https://advisories.mageia.org/MGASA-2025-0286.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2025-0286
Related
Published
2025-11-13T18:03:54Z
Modified
2025-11-13T17:24:00Z
Summary
Updated python-flask-cors packages fix security vulnerabilities
Details

Log Injection Vulnerability in corydolphin/flask-cors. (CVE-2024-1681) Improper Access Control in corydolphin/flask-cors. (CVE-2024-6221) Improper Regex Path Matching in corydolphin/flask-cors. (CVE-2024-6839) Inconsistent CORS Matching Due to Handling of '+' in URL Path in corydolphin/flask-cors. (CVE-2024-6844) Case-Insensitive Path Matching in corydolphin/flask-cors. (CVE-2024-6866)

References
Credits

Affected packages

Mageia:9 / python-flask-cors

Package

Name
python-flask-cors
Purl
pkg:rpm/mageia/python-flask-cors?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.10-1.1.mga9

Ecosystem specific

{
    "section": "core"
}