Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. flask-caching
  4. ›
  5. CVE-2021-33026

CVE-2021-33026: Improper Privilege Management

May 13, 2021 (updated November 9, 2023)

The Flask-Caching extension for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the cache, and execute Python code.

References

  • nvd.nist.gov/vuln/detail/CVE-2021-33026

Code Behaviors & Features

Detect and mitigate CVE-2021-33026 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 1.10.1

Solution

Unfortunately, there is no solution available yet.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-502: Deserialization of Untrusted Data

Source file

pypi/flask-caching/CVE-2021-33026.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:42 +0000.