Back

HIGH

python-flask: Denial of Service via crafted JSON file

Published Aug 20, 2018

Description

The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability appears to have been fixed in 0.12.3. NOTE: this may overlap CVE-2019-1010083.

Affected products

Remediation

Red Hat statement

This issue affects the versions of python-flask as shipped with Red Hat Enterprise Linux 7. Although Red Hat Satellite 6 contains the vulnerable component, the former is not affected due to python-flask only receiving JSON data created by other Red Hat Satellite 6 components, not user-controlled JSON data, which makes the attack unfeasible.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 20, 2018
Updated Aug 5, 2024
Reserved Aug 15, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 10, 2018
GHSA-562C-5R94-XH97