Package | Installed | Affected | Info |
---|---|---|---|
Flask | 3.0.3 | <3.1.1 |
show Affected versions of Flask (≤ 3.1.0) are vulnerable to incorrect fallback key configuration in session signing, leading to stale key usage instead of the intended current key. This flaw undermines session integrity, enabling remote attackers to forge or tamper with cookies via manipulated SECRET_KEY_FALLBACKS parameters. The vulnerability exists in the itsdangerous-based signing routines within flask.sessions (fallback key list ordering). |
Package | Installed | Affected | Info |
---|---|---|---|
Flask | 3.0.3 | <3.1.1 |
show Affected versions of Flask (≤ 3.1.0) are vulnerable to incorrect fallback key configuration in session signing, leading to stale key usage instead of the intended current key. This flaw undermines session integrity, enabling remote attackers to forge or tamper with cookies via manipulated SECRET_KEY_FALLBACKS parameters. The vulnerability exists in the itsdangerous-based signing routines within flask.sessions (fallback key list ordering). |
Package | Installed | Affected | Info |
---|---|---|---|
Flask | 3.0.3 | <3.1.1 |
show Affected versions of Flask (≤ 3.1.0) are vulnerable to incorrect fallback key configuration in session signing, leading to stale key usage instead of the intended current key. This flaw undermines session integrity, enabling remote attackers to forge or tamper with cookies via manipulated SECRET_KEY_FALLBACKS parameters. The vulnerability exists in the itsdangerous-based signing routines within flask.sessions (fallback key list ordering). |
Package | Installed | Affected | Info |
---|---|---|---|
Flask | 3.0.3 | <3.1.1 |
show Affected versions of Flask (≤ 3.1.0) are vulnerable to incorrect fallback key configuration in session signing, leading to stale key usage instead of the intended current key. This flaw undermines session integrity, enabling remote attackers to forge or tamper with cookies via manipulated SECRET_KEY_FALLBACKS parameters. The vulnerability exists in the itsdangerous-based signing routines within flask.sessions (fallback key list ordering). |
Package | Installed | Affected | Info |
---|---|---|---|
Flask | 3.0.3 | <3.1.1 |
show Affected versions of Flask (≤ 3.1.0) are vulnerable to incorrect fallback key configuration in session signing, leading to stale key usage instead of the intended current key. This flaw undermines session integrity, enabling remote attackers to forge or tamper with cookies via manipulated SECRET_KEY_FALLBACKS parameters. The vulnerability exists in the itsdangerous-based signing routines within flask.sessions (fallback key list ordering). |
Package | Installed | Affected | Info |
---|---|---|---|
Flask | 3.0.3 | <3.1.1 |
show Affected versions of Flask (≤ 3.1.0) are vulnerable to incorrect fallback key configuration in session signing, leading to stale key usage instead of the intended current key. This flaw undermines session integrity, enabling remote attackers to forge or tamper with cookies via manipulated SECRET_KEY_FALLBACKS parameters. The vulnerability exists in the itsdangerous-based signing routines within flask.sessions (fallback key list ordering). |
Package | Installed | Affected | Info |
---|---|---|---|
Flask | 3.0.3 | <3.1.1 |
show Affected versions of Flask (≤ 3.1.0) are vulnerable to incorrect fallback key configuration in session signing, leading to stale key usage instead of the intended current key. This flaw undermines session integrity, enabling remote attackers to forge or tamper with cookies via manipulated SECRET_KEY_FALLBACKS parameters. The vulnerability exists in the itsdangerous-based signing routines within flask.sessions (fallback key list ordering). |
Package | Installed | Affected | Info |
---|---|---|---|
Flask | 3.0.3 | <3.1.1 |
show Affected versions of Flask (≤ 3.1.0) are vulnerable to incorrect fallback key configuration in session signing, leading to stale key usage instead of the intended current key. This flaw undermines session integrity, enabling remote attackers to forge or tamper with cookies via manipulated SECRET_KEY_FALLBACKS parameters. The vulnerability exists in the itsdangerous-based signing routines within flask.sessions (fallback key list ordering). |
https://pyup.io/repos/github/fptiangco/rest-v2-python/python-3-shield.svg
[](https://pyup.io/repos/github/fptiangco/rest-v2-python/)
.. image:: https://pyup.io/repos/github/fptiangco/rest-v2-python/python-3-shield.svg :target: https://pyup.io/repos/github/fptiangco/rest-v2-python/ :alt: Python 3
<a href="https://pyup.io/repos/github/fptiangco/rest-v2-python/"><img src="https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/fptiangco/rest-v2-python/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/fptiangco/rest-v2-python/
{<img src="https://pyup.io/repos/github/fptiangco/rest-v2-python/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/fptiangco/rest-v2-python/]
https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg
[](https://pyup.io/repos/github/fptiangco/rest-v2-python/)
.. image:: https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg :target: https://pyup.io/repos/github/fptiangco/rest-v2-python/ :alt: Updates
<a href="https://pyup.io/repos/github/fptiangco/rest-v2-python/"><img src="https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg(Updates)!:https://pyup.io/repos/github/fptiangco/rest-v2-python/
{<img src="https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/fptiangco/rest-v2-python/]