CVE-2021-29621: medium-severity vulnerability in dpgaspar Flask-AppBuilder
Observable Response Discrepancy in Flask-AppBuilder
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Flask-AppBuilder allows attackers to discover which user accounts exist in the system by measuring how long the login page takes to respond. This happens because the server responds differently for valid usernames versus invalid ones, leaking information without needing a password.
A timing side-channel vulnerability in Flask-AppBuilder's database authentication (versions ≤ 3.2.3) enables unauthenticated user enumeration through response time discrepancies. An attacker can distinguish between valid and invalid usernames by analyzing login response times, facilitating targeted credential attacks. Mitigation requires upgrade to version 3.3.0 or later.
In the same product, most dangerous first.