VDB
Sign up
HIGH8.8

PYSEC-2022-43135

Quick fix

PYSEC-2022-43135 — freetakserver: upgrade to the fixed version with the command below.

pip install --upgrade 'freetakserver>=1.9.8.5'

Details

FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass authentication or escalate privileges.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/freetakserver
Introduced in: 0Fixed in: 1.9.8.5
Fixpip install --upgrade 'freetakserver>=1.9.8.5'

References