<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:34:11 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-25128 — Flask-AppBuilder incorrect authentication when using auth type OpenID</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-25128</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; dpgaspar Flask-AppBuilder&lt;/p&gt;
&lt;p&gt;Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; dpgaspar Flask-AppBuilder&lt;/p&gt;
&lt;p&gt;Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-25128</guid>
    </item>
    <item>
      <title>GHSA-j2pw-vp55-fqqj — Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-j2pw-vp55-fqqj</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Flask-AppBuilder&lt;/p&gt;
&lt;p&gt;### Impact
When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend.&lt;/p&gt;
&lt;p&gt;This vulnerability is only exploitable when the application is using the old (deprecated 10 years ago) OpenID 2.0 authorization protocol (which is very different from the popular OIDC - Open ID Connect - popular protocol used today). Currently, this protocol is regarded as legacy, with significantly reduced usage and not supported for several years by major authorization providers.&lt;/p&gt;
&lt;p&gt;### Patches
Upgrade to Flask-AppBuilder 4.3.11&lt;/p&gt;
&lt;p&gt;### Workarounds
If upgrade is not possible add the following to your config:&lt;/p&gt;
&lt;p&gt;```
from flask import flash, redirect
from flask_appbuilder import expose
from flask_appbuilder.security.sqla.manager import SecurityManager
from flask_appbuilder.security.views import AuthOIDView
from flask_appbuilder.security.forms import LoginForm_oid&lt;/p&gt;
&lt;p&gt;basedir = os.path.abspath(os.path.dirname(__file__))&lt;/p&gt;
&lt;p&gt;class FixedOIDView(AuthOIDView):
    @expose(&amp;#34;/login/&amp;#34;, methods=[&amp;#34;GET&amp;#34;, &amp;#34;POST&amp;#34;])
    def login(self, flag=True):
        form = LoginForm_oid()
        if form.validate_on_submit():
            identity_url = None
            for provider in self.appbuilder.sm.openid_providers:
                if provider.get(&amp;#34;url&amp;#34;) == form.openid.da…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Flask-AppBuilder&lt;/p&gt;
&lt;p&gt;### Impact
When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend.&lt;/p&gt;
&lt;p&gt;This vulnerability is only exploitable when the application is using the old (deprecated 10 years ago) OpenID 2.0 authorization protocol (which is very different from the popular OIDC - Open ID Connect - popular protocol used today). Currently, this protocol is regarded as legacy, with significantly reduced usage and not supported for several years by major authorization providers.&lt;/p&gt;
&lt;p&gt;### Patches
Upgrade to Flask-AppBuilder 4.3.11&lt;/p&gt;
&lt;p&gt;### Workarounds
If upgrade is not possible add the following to your config:&lt;/p&gt;
&lt;p&gt;```
from flask import flash, redirect
from flask_appbuilder import expose
from flask_appbuilder.security.sqla.manager import SecurityManager
from flask_appbuilder.security.views import AuthOIDView
from flask_appbuilder.security.forms import LoginForm_oid&lt;/p&gt;
&lt;p&gt;basedir = os.path.abspath(os.path.dirname(__file__))&lt;/p&gt;
&lt;p&gt;class FixedOIDView(AuthOIDView):
    @expose(&amp;#34;/login/&amp;#34;, methods=[&amp;#34;GET&amp;#34;, &amp;#34;POST&amp;#34;])
    def login(self, flag=True):
        form = LoginForm_oid()
        if form.validate_on_submit():
            identity_url = None
            for provider in self.appbuilder.sm.openid_providers:
                if provider.get(&amp;#34;url&amp;#34;) == form.openid.da…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-j2pw-vp55-fqqj</guid>
    </item>
  </channel>
</rss>
