Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4197-1 | python-flask-cors security update |
EUVD |
EUVD-2024-1152 | corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. This vulnerability allows attackers to corrupt log files, potentially covering tracks of other attacks, confusing log post-processing tools, and forging log entries. The issue is due to improper output neutralization for logs. |
Github GHSA |
GHSA-84pr-m4jr-85g5 | flask-cors vulnerable to log injection when the log level is set to debug |
Ubuntu USN |
USN-7612-1 | Flask-CORS vulnerabilities |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:corydolphin:flask-cors:-:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Wed, 30 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:corydolphin:flask-cors:4.0.0:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-11-03T19:29:18.706Z
Reserved: 2024-02-20T19:13:22.208Z
Link: CVE-2024-1681
Updated: 2025-11-03T19:29:18.706Z
Status : Modified
Published: 2024-04-19T20:15:09.273
Modified: 2025-11-03T20:16:09.027
Link: CVE-2024-1681
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:07:50Z
Debian DLA
EUVD
Github GHSA
Ubuntu USN