Executive brief
A vulnerability in the Flask-Cors library, which manages cross-origin resource sharing for web applications, could allow external websites to access resources on a company's private internal network. By default, the library incorrectly signals to web browsers that private network requests are permitted, potentially exposing sensitive internal data or services to unauthorized parties. This could lead to data breaches or unauthorized access to internal systems that were intended to be isolated from the public internet.
Technical details
A vulnerability in Flask-Cors version 4.0.1 (and earlier) causes the 'Access-Control-Allow-Private-Network' CORS header to be set to 'true' by default without a configuration option to disable it. This behavior violates the Private Network Access (PNA) specification, which is designed to prevent public websites from making unauthorized requests to internal or local network endpoints. An attacker can exploit this by hosting a malicious website that, when visited by a user inside a private network, can successfully perform cross-origin requests to internal services that use the vulnerable Flask-Cors configuration. This can result in the unauthorized disclosure of sensitive information from internal APIs. The issue is resolved in version 4.0.2.
Affected products
- corydolphin Flask-Cors < 4.0.2
Timeline
- 2024-08-18: advisory: GitHub Advisory published
- 2024-08-18: disclosed: NVD publication date