CVE-2021-32618 is an open redirect vulnerability affecting the Python "Flask-Security-Too" package, which is used to add security features to Flask applications. It allows an attacker to craft a malicious URL that, when clicked by a user, redirects them from a legitimate Flask application to an arbitrary external website. This is due to lenient URL validation that can be bypassed by specific URL formats. The vulnerability has a CVSS score of 6.1 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and potentially leading to low impact on confidentiality and integrity. However, its practical severity is often mitigated as the common Werkzeug WSGI layer typically prevents this redirect unless explicitly configured otherwise. While there is no evidence of active exploitation, Nuclei templates exist for detecting this vulnerability. It has garnered significant community discussion and media coverage, highlighting awareness despite its medium severity and the common mitigating factor.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:flask-security_project:flask-security:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.