CVE-2025-24023

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.
Configurations

No configuration.

History

03 Mar 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-03 16:15

Updated : 2025-03-03 16:15


NVD link : CVE-2025-24023

Mitre link : CVE-2025-24023

CVE.ORG link : CVE-2025-24023


JSON object : View

Products Affected

No product.

CWE
CWE-204

Observable Response Discrepancy