CVE-2024-27083: Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)

Published Feb 28, 2024
·
Updated

Impact A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser.

Impacted versions: Flask-AppBuilder version 4.1.4 up to and including 4.2.0

Patches This issue was introduced on 4.1.4 and patched on 4.2.1, user's should upgrade to 4.2.1 or newer versions.

Other sources

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user's browser. This issue was introduced on 4.1.4 and patched on 4.2.1.

MITRE

Affected Software

2 affected componentsFixes available
dpgaspar Flask-AppBuilder>=4.1.4<4.2.1
pip/Flask-AppBuilder>=4.1.4<4.2.1
4.2.1

Event History

Feb 28, 2024
CVE Published
via MITRE·03:34 PM
Data Sourced
via MITRE·03:34 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:37 PM
Feb 29, 2024
Data Sourced
via NVD·01:44 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-27083?

CVE-2024-27083 has been classified as a critical severity vulnerability due to its potential for Cross-Site Scripting attacks.

2

What types of attacks can be performed using CVE-2024-27083?

An attacker can exploit CVE-2024-27083 through Cross-Site Scripting to execute malicious JavaScript in the context of the user's session.

3

How do I fix CVE-2024-27083?

To fix CVE-2024-27083, you should upgrade to Flask-AppBuilder version 4.2.1 or later.

4

Which software is affected by CVE-2024-27083?

CVE-2024-27083 affects Flask-AppBuilder versions 4.1.4 to 4.2.0, specifically during the OAuth login process.

5

What is the impact of CVE-2024-27083 on users?

Users can be tricked into executing malicious scripts if they visit a specially crafted URL targeting the OAuth login page.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203