Flask Security Project maintains a focused Python web-application security extension for the Flask framework, providing authentication and authorization functionality to Flask-based applications. The observed vulnerability landscape for this vendor centers on its core Flask Security product, with weakness classes emerging around authentication and access-control mechanisms. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flask Security Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-32618MEDIUM The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on t | May 17, 2021 | 6.1 | 30 | NO | YES |
CVE-2021-23385MEDIUM This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redi | Aug 2, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flask Security Project.
Media articles that mention a CVE ID that affects a product developed by Flask Security Project — matched by CVE ID, not by vendor name.