CVE-2024-27083: Flask-AppBuilder's OAuth login page subject to Cross Site Scripting (XSS)
(updated )
A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code that would get executed on the user’s browser.
Impacted versions: Flask-AppBuilder version 4.1.4 up to and including 4.2.0
References
Code Behaviors & Features
Detect and mitigate CVE-2024-27083 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →