CVE-2024-45314

3.6
LOWCVSS v3.1 Base Score
0.27%
LOW RiskEPSS (17th percentile)

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not possible, configure one's web server to send the specific HTTP headers for `/login` per the directions provided in the GitHub Security Advisory.

Published: 9/4/2024
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

3.6LOW

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N

EPSS Score (Exploitation Probability)

0.27%LOW Exploitation Risk
17th percentile

This vulnerability has a 0.27% probability of being exploited in the next 30 days, ranking higher than 17% of all scored CVEs.

CWE Classification

Advertisement