CVE-2020-25032
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
HIGH · CVSS 7.5
EPSS 0.00897
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0