praetorian-colby-morgan reports:
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. [source]
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9.
It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.
Copyright © 2003-2005 Jacques Vidrine and contributors. Please see the source of this document for full copyright information.