Skip to main content

Observable Response Discrepancy

CVE-2025-24023

Severity Low
Score 3.7/10

Summary

Flask-AppBuilder is an application development framework. Flask-AppBuilder versions prior to 4.5.3rc1, allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login.

  • HIGH
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • LOW
  • NONE

CWE-204 - Observable Response Discrepancy

The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

References

Advisory Timeline

  • Published