| Package | Installed | Affected | Info |
|---|---|---|---|
| Flask | 3.0.3 | <3.1.3 |
show Affected versions of the Flask package are vulnerable to Information Disclosure due to missing cache-variation headers when the session object is accessed via certain code paths. In Flask’s session handling, accessing flask.session is intended to set a Vary: Cookie response header, but session key-only access patterns (such as using the Python in operator to test for a key without reading or mutating session values) can bypass the logic that adds the header. |
| Package | Installed | Affected | Info |
|---|---|---|---|
| Flask | 3.0.3 | <3.1.3 |
show Affected versions of the Flask package are vulnerable to Information Disclosure due to missing cache-variation headers when the session object is accessed via certain code paths. In Flask’s session handling, accessing flask.session is intended to set a Vary: Cookie response header, but session key-only access patterns (such as using the Python in operator to test for a key without reading or mutating session values) can bypass the logic that adds the header. |
https://pyup.io/repos/github/fptiangco/rest-v2-python/python-3-shield.svg
[](https://pyup.io/repos/github/fptiangco/rest-v2-python/)
.. image:: https://pyup.io/repos/github/fptiangco/rest-v2-python/python-3-shield.svg
:target: https://pyup.io/repos/github/fptiangco/rest-v2-python/
:alt: Python 3
<a href="https://pyup.io/repos/github/fptiangco/rest-v2-python/"><img src="https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/fptiangco/rest-v2-python/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/fptiangco/rest-v2-python/
{<img src="https://pyup.io/repos/github/fptiangco/rest-v2-python/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/fptiangco/rest-v2-python/]
https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg
[](https://pyup.io/repos/github/fptiangco/rest-v2-python/)
.. image:: https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg
:target: https://pyup.io/repos/github/fptiangco/rest-v2-python/
:alt: Updates
<a href="https://pyup.io/repos/github/fptiangco/rest-v2-python/"><img src="https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg(Updates)!:https://pyup.io/repos/github/fptiangco/rest-v2-python/
{<img src="https://pyup.io/repos/github/fptiangco/rest-v2-python/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/fptiangco/rest-v2-python/]