Junglewise Threat Intelligence

CVE-2025-24023: PYSEC-2025-15 - Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existin

CVE-2025-24023 · Severity: low · CVSS 3.1 · Published 2025-03-03

Technologies: flask-appbuilder (PyPI). Vendors: PyPI.

Executive brief

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.

Affected products

  • PyPI flask-appbuilder

Related threats