CVE-2025-24023

Publication date

2025-03-03 15:25:55

Family

GitHub_M

State

PUBLISHED

Description

Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3.