Security: dpgaspar/Flask-AppBuilder
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Authentication bypass vulnerability when using non AUTH_DBGHSA-765j-9r45-w2q2 published
Sep 11, 2025 by dpgasparModerate -
Open redirect vulnerability using HTTP host injectionGHSA-99pm-ch96-ccp2 published
May 16, 2025 by dpgasparModerate -
Observable Response Discrepancy in flask-appbuilderGHSA-p8q5-cvwx-wvwp published
Mar 3, 2025 by dpgasparLow -
Login form allows browser to cache sensitive fieldsGHSA-fw5r-6m3x-rh7p published
Sep 4, 2024 by dpgasparLow -
OAuth login page subject to Cross Site Scripting (XSS)GHSA-fqxj-46wg-9v84 published
Feb 28, 2024 by dpgasparModerate -
Incorrect authentication when using auth type OpenIDGHSA-j2pw-vp55-fqqj published
Feb 28, 2024 by dpgasparModerate -
Possible disclosure of sensitive information on user errorGHSA-jhpr-j7cq-3jp3 published
Jun 22, 2023 by dpgasparLow -
No Rate Limiting on Login AUTH DBGHSA-9hcr-9hcv-x6pv published
Apr 10, 2023 by dpgasparLow -
Possible to infer sensitive information through query stringsGHSA-32ff-4g79-vgfc published
Jul 28, 2022 by dpgasparModerate -
Possible URL Redirection to Untrusted Site ('Open Redirect') in Flask-AppBuilderGHSA-2ccw-7px8-vmpf published
Mar 24, 2022 by dpgasparLow