Summary: Flask-Security could be made to bypass URL validation and redirect to arbitary URL. Software Description: - flask-security: Simple security for Flask apps (Python 3) Details: Naom Moshe discovered that Flask-Security incorrectly validated URLs. An attacker could use this issue to redirect users to arbitrary URLs.
Created python-flask-security-too tracking bugs for this issue: Affects: fedora-all [bug 2283826]