Junglewise Threat Intelligence

CVE-2020-25032: PYSEC-2020-43 - An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private reso

CVE-2020-25032 · Severity: low · CVSS 3.1 · Published 2020-08-31

Technologies: Flask-Cors (PyPI). Vendors: PyPI.

Executive brief

An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

Affected products

  • PyPI Flask-Cors

Related threats