Skip to content

Deserialization of Untrusted Data in Flask-Caching

Moderate severity GitHub Reviewed Published Jun 18, 2021 to the GitHub Advisory Database • Updated Aug 16, 2023

Package

pip Flask-Caching (pip)

Affected versions

<= 1.10.1

Patched versions

None

Description

Flask-Cache adds easy cache support to Flask. The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the cache, and execute Python code.

However, this is not a high-severity issue, as for an attack like this to work, an attacker must:

  1. Be able to write arbitrary values to the cache
  2. Be able to generate a cache key that will collide with a value being read by the application
  3. Cause the application to read a maliciously-injected value

Any situation where all 3 of those is true is a situation where the application has larger problems; for example, if someone's able to inject malicious cached rendered pages into a Flask app's cache, then they can make the website say literally anything they want, regardless of whether it involves the execution of remote code. Basically, the Pickle vulnerability follows from a website already being extremely vulnerable (due to conditions 1 and 2 being met).

References

Published by the National Vulnerability Database May 13, 2021
Reviewed May 17, 2021
Published to the GitHub Advisory Database Jun 18, 2021
Last updated Aug 16, 2023

Severity

Moderate
4.2
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
High
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N

CVE ID

CVE-2021-33026

GHSA ID

GHSA-656c-6cxf-hvcv

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.