Red Hat Bugzilla – Bug 1623131
CVE-2018-1000656 python-flask: Denial of Service via crafted JSON file
Last modified: 2018-10-23 11:32:54 EDT
A flaw was found in The Pallets Project flask version Before 0.12.3. An Improper Input Validation vulnerability in flask that can result in a large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. References: https://github.com/pallets/flask/pull/2691
Created python-flask tracking bugs for this issue: Affects: fedora-all [bug 1623179]
Statement: This issue affects the versions of python-flask as shipped with Red Hat Enterprise Linux 7.