suse · CVE-2018-1000656

Quick triage

Priority: low Published: 2021-05-30 14:20:43 UTC Updated: 2025-02-17 02:26:56 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-1000656 severity low: SUSE including 9 source package names (python-Flask, python2-Flask, …), 22 product×package rows across 14 product lines (HPE Helion OpenStack 8, SUSE Enterprise Storage 7, … (14 product lines)): Known Not Affected 13, Fixed 6, Will Not Fix 3.

Description:

The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability appears to have been fixed in 0.12.3. NOTE: this may overlap CVE-2019-1010083.

cvelogic Threat Intelligence