CVE-2021-23385 is an open redirect vulnerability affecting all versions of the unmaintained Flask-Security package. It allows an attacker to bypass URL validation in the get_post_logout_redirect and get_post_login_redirect functions, redirecting users to arbitrary URLs via specially crafted input like \\\evil.com/path. This vulnerability has a CVSS score of 6.1 (Medium) and is exploitable only when using an alternative WSGI server or modifying Werkzeug's default behavior, requiring user interaction. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:flask-security_project:flask-security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.