GHSA-j2pw-vp55-fqqj · Severity: critical · Ecosystem: pip — Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege access if a custom OpenID service is deployed by the attacker and accessible by the backend. This vulnerability is only exploitable when the application is using the OpenID 2.0 authorization protocol. Upgrade to Flask-AppBuilder 4.3.11 to fix the vulnerability.
Conclusion & alert: CVE-2024-25128 is rated Moderate Risk (55/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.86%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.96% | 0.86% | -0.10% |
| 2 | 2026-03-04 | 0.42% | 0.96% | +0.54% |
| 3 | 2026-03-01 | — | 0.42% | — |
Full EPSS history (34 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
GHSA-j2pw-vp55-fqqj · Severity: critical · Ecosystem: pip — Flask-AppBuilder vulnerable to incorrect authentication when using auth type OpenID
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2024-25128 medium priority: Ubuntu has no source package entries, 0 status rows across 0 suites (none): no status rows. | https://ubuntu.com/security/CVE-2024-25128 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| dpgaspar | flask-appbuilder | < 4.3.11 | cpe:2.3:a:dpgaspar:flask-appbuilder:*:*:*:*:*:*:*:* |