Your message dated Wed, 11 Jun 2025 06:33:59 +0000
with message-id <[email protected]>
and subject line Bug#1100988: fixed in python-flask-cors 6.0.1-1
has caused the Debian Bug report #1100988,
regarding python-flask-cors: CVE-2024-6866 CVE-2024-6844 CVE-2024-6839
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1100988: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1100988
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-flask-cors
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerabilities were published for python-flask-cors.

CVE-2024-6866[0]:
| corydolphin/flask-cors version 4.01 contains a vulnerability where
| the request path matching is case-insensitive due to the use of the
| `try_match` function, which is originally intended for matching
| hosts. This results in a mismatch because paths in URLs are case-
| sensitive, but the regex matching treats them as case-insensitive.
| This misconfiguration can lead to significant security
| vulnerabilities, allowing unauthorized origins to access paths meant
| to be restricted, resulting in data exposure and potential data
| leaks.

https://huntr.com/bounties/808c11af-faee-43a8-824b-b5ab4f62b9e6


CVE-2024-6844[1]:
| A vulnerability in corydolphin/flask-cors version 4.0.1 allows for
| inconsistent CORS matching due to the handling of the '+' character
| in URL paths. The request.path is passed through the unquote_plus
| function, which converts the '+' character to a space ' '. This
| behavior leads to incorrect path normalization, causing potential
| mismatches in CORS configuration. As a result, endpoints may not be
| matched correctly to their CORS settings, leading to unexpected CORS
| policy application. This can cause unauthorized cross-origin access
| or block valid requests, creating security vulnerabilities and
| usability issues.

https://huntr.com/bounties/731a6cd4-d05f-4fe6-8f5b-fe088d7b34e0


CVE-2024-6839[2]:
| corydolphin/flask-cors version 4.0.1 contains an improper regex path
| matching vulnerability. The plugin prioritizes longer regex patterns
| over more specific ones when matching paths, which can lead to less
| restrictive CORS policies being applied to sensitive endpoints. This
| mismatch in regex pattern priority allows unauthorized cross-origin
| access to sensitive data or functionality, potentially exposing
| confidential information and increasing the risk of unauthorized
| actions by malicious actors.

https://huntr.com/bounties/403eb1fc-86f4-4820-8eba-0f3dfae9f2b4



If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2024-6866
    https://www.cve.org/CVERecord?id=CVE-2024-6866
[1] https://security-tracker.debian.org/tracker/CVE-2024-6844
    https://www.cve.org/CVERecord?id=CVE-2024-6844
[2] https://security-tracker.debian.org/tracker/CVE-2024-6839
    https://www.cve.org/CVERecord?id=CVE-2024-6839

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: python-flask-cors
Source-Version: 6.0.1-1
Done: Carsten Schoenert <[email protected]>

We believe that the bug you reported is fixed in the latest version of
python-flask-cors, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Carsten Schoenert <[email protected]> (supplier of updated 
python-flask-cors package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 11 Jun 2025 08:05:36 +0200
Source: python-flask-cors
Architecture: source
Version: 6.0.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Carsten Schoenert <[email protected]>
Closes: 1100988
Changes:
 python-flask-cors (6.0.1-1) unstable; urgency=medium
 .
   * [e698dc8] New upstream version 6.0.1
     Fixed CVE issues in upstream version 6.0.1:
     CVE-2024-6839: Flask-CORS improper regex path matching vulnerability
     The added fix for this issue in version 6.0.0 did correct the problem not
     fully and needed a further source modification.
     (Closes: #1100988)
Checksums-Sha1:
 75a6d1ac086ef086cf4426038e826c293365ee17 2328 python-flask-cors_6.0.1-1.dsc
 0dd62ad5e278ea766e6500668ad5bf114f7d9ba5 87264 
python-flask-cors_6.0.1.orig.tar.gz
 1e0ca2bf47ea9d04dd3dd34711ff090deea527c3 8076 
python-flask-cors_6.0.1-1.debian.tar.xz
 55f8b49bd6952bc405875ba517e1849549f0045a 8714 
python-flask-cors_6.0.1-1_amd64.buildinfo
Checksums-Sha256:
 ce8cf430f7da50f5449a430d66b0b9959f93db9c0cd5fcb9be29d2c05616d8f5 2328 
python-flask-cors_6.0.1-1.dsc
 959f1fd2fd83a33b8dbb447f66f5045e61fa5ea6232fbaea2bed02f10cb8aa1a 87264 
python-flask-cors_6.0.1.orig.tar.gz
 f647037aeaa5ce7209a08457be6eb60611523fff348970f1c60007f8ef1cce33 8076 
python-flask-cors_6.0.1-1.debian.tar.xz
 d7deb197d430ca97370cd0648f50eec5136efb337c1d11e6b2c312c5822fff0c 8714 
python-flask-cors_6.0.1-1_amd64.buildinfo
Files:
 8312e4f40cfedf63e23e7c6fdc254f2c 2328 python optional 
python-flask-cors_6.0.1-1.dsc
 e0b1f293472bb251f0973ede779b8ea1 87264 python optional 
python-flask-cors_6.0.1.orig.tar.gz
 f653a254f82149e333745f8f39725610 8076 python optional 
python-flask-cors_6.0.1-1.debian.tar.xz
 9f20987f9c3d0d7542ed35205f63738c 8714 python optional 
python-flask-cors_6.0.1-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJMBAEBCgA2FiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmhJHuQYHGMuc2Nob2Vu
ZXJ0QHQtb25saW5lLmRlAAoJEIMBYBQlHR2wdKcP/idk6H8FCfQHnHiicC8H4RoK
K+ECdY92IOchl7terFQoixMu58U6T3BMhg6wzw0mVZb/MX17ZEw1rxduxhAmmeLD
MpC3qQsUONIWEHQu0csS2dbqwyQrjTGTkei4ovkLrVEYPonxdjkYe80zPNdMITul
gTSU+cDe83GiHkQtXncLfCetq3lxpyBoGSOTDGaCgbRaVmmdOj1Km7leKuO0wZIh
/08VJ/E8jhr2OvlDiCH+zFoUW0KfBImo7TJGTCvUL4Nfnyr8u3+/alOLI74OZLtP
RoK6Nh2hnODrsjaHWgrWCZdfp5qG4AYT8unVeSrz9S22RJn4etRyZBevriV1JVAV
9gd+ZzpAbplT5dRugXnOiXyUnjpG6HXq6EkKRk/WU05jlkS6VvXvwX/qpzpnQrg5
BzobCMDMMqvTLCUG5crk8cy8Xin+6KR/M3ZkpQgu/qr7hvxf8xwMv8BDvFx5QxLE
9L+04LTvfBgzWqijD29jQwJIRwV0LqXMCPqBdvyGQbuXQEUZxkD4MQErMPO23PdG
zX5wtG6EMX3tivM1UMjBVlXM7fjiOkhqXqTB2XYK19yVFEd+EIZFzgsVlJehhsfO
DtORUs72RsmGoN2/lN+bEf1LXcEDARdlysCTQvCmWt7knCMe0A6tJCE47K2RrE17
tT3hCVLZwJ+ATdI4rSUf
=AMrx
-----END PGP SIGNATURE-----

Attachment: pgpg6pADDpgp5.pgp
Description: PGP signature


--- End Message ---

Reply via email to