CVE-2018-1000656

Description

The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability appears to have been fixed in 0.12.3. NOTE: this may overlap CVE-2019-1010083.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.583

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-1000656 are fixed in Python-flask 0.12.3Windows
(RHSA-2020:0870) python-flask security update python-flask-0.10.1-5.el7_7.noarch.rpmLinux
Micro web framework based on Werkzeug and Jinja2 (USN-4378-1) python-flask_0.10.1-2ubuntu0.1_all.debLinux
Micro web framework based on Werkzeug and Jinja2 (USN-4378-1) python-flask_0.12.2-3ubuntu0.1_all.debLinux
Micro web framework based on Werkzeug and Jinja2 (USN-4378-1) python3-flask_0.10.1-2ubuntu0.1_all.debLinux
Micro web framework based on Werkzeug and Jinja2 (USN-4378-1) python3-flask_0.12.2-3ubuntu0.1_all.debLinux
Vulnerabilities CVE-2018-1000656 are fixed in Python-flask for linux 0.12.3Linux
Improper Input Validation Vulnerability (CVE-2018-1000656)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234