CVE-2024-6839

CVSS 3.0 Score 4.3 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 41

Summary

CVE-2024-6839 is a vulnerability affecting the corydolphin/flask-cors library version 4.0.1. This issue involves a flaw in the regex path matching functionality, where longer patterns take priority over more specific ones. This can lead to less restrictive CORS policies being applied to sensitive endpoints, potentially allowing unauthorized cross-origin access. Malicious actors could exploit this vulnerability to gain access to confidential information or execute unauthorized actions, increasing the risk of data breaches and security incidents.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share