Vulnerability Name:

CVE-2020-25032 (CCN-187626)

Assigned:2020-08-31
Published:2020-08-31
Updated:2022-04-28
Summary:An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
7.2 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
5.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-22
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2020-25032

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:1393

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:1415

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:1423

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2020:1446

Source: XF
Type: UNKNOWN
flaskcors-cve202025032-dir-traversal(187626)

Source: CCN
Type: Flask-CORS GIT Repository
Flask-CORS

Source: MISC
Type: Third Party Advisory
https://github.com/corydolphin/flask-cors/releases/tag/3.0.9

Source: DEBIAN
Type: Third Party Advisory
DSA-4775

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2020-25032

Vulnerable Configuration:Configuration 1:
  • cpe:/a:flask-cors_project:flask-cors:*:*:*:*:*:*:*:* (Version < 3.0.9)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:flask-cors_project:flask-cors:3.0.8:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:202025032
    V
    CVE-2020-25032
    2022-06-30
    oval:org.opensuse.security:def:113249
    P
    python36-Flask-Cors-3.0.10-1.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:64818
    P
    Security update for openssh (Important)
    2021-12-06
    oval:org.opensuse.security:def:64609
    P
    Security update for webkit2gtk3 (Important)
    2021-11-03
    oval:org.opensuse.security:def:64608
    P
    Security update for libvirt (Moderate)
    2021-10-29
    oval:org.opensuse.security:def:106661
    P
    python36-Flask-Cors-3.0.10-1.3 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:61654
    P
    shim-15+git47-1.5 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61677
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63204
    P
    freeradius-server-3.0.16-3.3.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63205
    P
    gnuplot-5.2.2-3.3.29 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61653
    P
    sharutils-4.15.2-2.21 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:60340
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:63471
    P
    flac-1.3.2-3.6.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63125
    P
    kernel-azure-5.3.18-36.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63093
    P
    libcgroup-devel-0.41.rc1-1.10.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63443
    P
    libxslt1-32bit-1.1.32-3.8.24 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63327
    P
    freeradius-server-3.0.21-3.6.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63465
    P
    dia-0.97.3-4.3.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63102
    P
    reiserfs-kmp-default-5.3.18-57.3 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63496
    P
    libsybdb5-1.1.36-3.3.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63437
    P
    libsndfile1-32bit-1.0.28-5.5.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63336
    P
    libcacard-devel-2.5.3-1.27 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62211
    P
    libruby2_5-2_5-2.5.9-4.17.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62753
    P
    gnome-shell-3.34.5-8.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62119
    P
    libXRes1-1.2.0-1.18 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62313
    P
    python3-waitress-1.4.3-3.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:64716
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:62846
    P
    build-20180329-1.10 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:63068
    P
    reiserfs-kmp-default-4.12.14-23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:63065
    P
    openldap2-2.4.46-7.10 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:63061
    P
    java-1_8_0-ibm-1.8.0_sr5.11-1.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:63546
    P
    libmwaw-0_3-3-0.3.13-2.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64514
    P
    Security update for ceph (Important)
    2021-06-02
    oval:org.opensuse.security:def:63074
    P
    libopenssl-1_0_0-devel-1.0.2p-3.14.2 on GA media (Moderate)
    2021-04-29
    oval:org.opensuse.security:def:64472
    P
    Security update for clamav (Important)
    2021-04-14
    oval:org.opensuse.security:def:59856
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:60456
    P
    Security update for tomcat (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:60300
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:74580
    P
    Security update for the Linux Kernel (Important)
    2021-01-14
    oval:org.opensuse.security:def:61058
    P
    Security update for openexr (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:62407
    P
    gcab-1.1-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61742
    P
    freetype2-devel-2.10.1-4.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62653
    P
    libSoundTouch0-1.8.0-3.11.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63298
    P
    rarpd-s20161105-6.10 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63581
    P
    imobiledevice-tools-1.2.0+git20170122.45fda81-1.44 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63271
    P
    libct4-1.1.36-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63387
    P
    apache-commons-beanutils-1.9.2-2.46 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62645
    P
    ibus-1.5.22-2.21 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63564
    P
    NetworkManager-applet-1.8.10-3.39 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62443
    P
    libgypsy-devel-0.9-2.30 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63404
    P
    apache-commons-beanutils-1.9.4-1.68 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61846
    P
    libmspack-devel-0.6-3.8.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61743
    P
    fuse-2.9.7-3.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61766
    P
    hardlink-1.0+git.e66999f-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62646
    P
    ibus-chewing-1.6.1-1.53 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62539
    P
    libXi6-32bit-1.7.9-1.23 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63308
    P
    uuidd-2.33.1-4.5.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61937
    P
    pam_ssh-2.1-2.27 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62669
    P
    libgme-devel-0.6.2-1.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62972
    P
    perl-Archive-Extract-0.80-1.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:60552
    P
    sysvinit-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60978
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:60761
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:63691
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64876
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:64360
    P
    libopenssl-1_1-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:75063
    P
    Security update for python-Flask-Cors (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74454
    P
    Security update for libtomcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60111
    P
    Security update for the Linux Kernel (Live Patch 30 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:60815
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60718
    P
    Security update for python3-requests (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:61028
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:64143
    P
    Security update for libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60672
    P
    Security update for python-PyKMIP (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64258
    P
    gdk-pixbuf-loader-rsvg on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60790
    P
    Security update for ansible, ardana-ansible, ardana-cinder, ardana-glance, ardana-mq, ardana-nova, ardana-osconfig, crowbar-core, crowbar-openstack, documentation-suse-openstack-cloud, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-monasca-installer, openstack-neutron, openstack-nova, python-Django, python-Flask-Cors, python-Pillow, python-ardana-packager, python-keystoneclient, python-keystonemiddleware, python-kombu, python-straight-plugin, python-urllib3, release-notes-suse-openstack-cloud, storm, storm-kit, venv-openstack-cinder, venv-openstack-swift (Important)
    2020-12-01
    oval:org.opensuse.security:def:64152
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:74930
    P
    Security update for file-roller (Low)
    2020-12-01
    oval:org.opensuse.security:def:63767
    P
    Recommended update for NetworkManager (Low)
    2020-12-01
    oval:org.opensuse.security:def:60600
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:60041
    P
    Security update for bash (Important)
    2020-12-01
    oval:org.opensuse.security:def:60937
    P
    Security update for galera-3, mariadb, mariadb-connector-c (Important)
    2020-12-01
    oval:org.opensuse.security:def:63914
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:60634
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60711
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:64018
    P
    Security update for postgresql10 (Low)
    2020-12-01
    oval:org.opensuse.security:def:64988
    P
    Security update for permissions (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64402
    P
    libwavpack1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60899
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:84056
    P
    Security update for ansible, ardana-ansible, ardana-cinder, ardana-glance, ardana-mq, ardana-nova, ardana-osconfig, crowbar-core, crowbar-openstack, documentation-suse-openstack-cloud, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-monasca-installer, openstack-neutron, openstack-nova, python-Django, python-Flask-Cors, python-Pillow, python-ardana-packager, python-keystoneclient, python-keystonemiddleware, python-kombu, python-straight-plugin, python-urllib3, release-notes-suse-openstack-cloud, storm, storm-kit, venv-openstack-cinder, venv-openstack-swift (Important)
    2020-11-12
    oval:org.opensuse.security:def:84511
    P
    Security update for ansible, ardana-ansible, ardana-cinder, ardana-glance, ardana-mq, ardana-nova, ardana-osconfig, crowbar-core, crowbar-openstack, documentation-suse-openstack-cloud, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-monasca-installer, openstack-neutron, openstack-nova, python-Django, python-Flask-Cors, python-Pillow, python-ardana-packager, python-keystoneclient, python-keystonemiddleware, python-kombu, python-straight-plugin, python-urllib3, release-notes-suse-openstack-cloud, storm, storm-kit, venv-openstack-cinder, venv-openstack-swift (Important)
    2020-11-12
    oval:org.opensuse.security:def:103049
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-17
    oval:org.opensuse.security:def:96359
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-17
    oval:org.opensuse.security:def:109706
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-17
    oval:org.opensuse.security:def:96353
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-14
    oval:org.opensuse.security:def:109700
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-14
    oval:org.opensuse.security:def:103043
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-14
    oval:org.opensuse.security:def:93515
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-12
    oval:org.opensuse.security:def:100228
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-12
    oval:org.opensuse.security:def:110758
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-09
    oval:org.opensuse.security:def:110204
    P
    Security update for python-Flask-Cors (Moderate)
    2020-09-09
    BACK
    flask-cors_project flask-cors *
    debian debian linux 10.0
    opensuse backports sle 15.0 sp1
    opensuse backports sle 15.0 sp2
    opensuse leap 15.1
    opensuse leap 15.2
    flask-cors_project flask-cors 3.0.8