cve/2024/CVE-2024-1681.md
2025-09-29 16:08:36 +00:00

1019 B

CVE-2024-1681

Description

corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. This vulnerability allows attackers to corrupt log files, potentially covering tracks of other attacks, confusing log post-processing tools, and forging log entries. The issue is due to improper output neutralization for logs.

POC

Reference

No PoCs from references.

Github