{"id":"GHSA-fjq3-5pxw-4wj4","summary":"Cross-Site Request Forgery in Webargs","details":"flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input. If the request body is valid JSON, it will accept it even if the content type is application/x-www-form-urlencoded. This allows for JSON POST requests to be made across domains, leading to CSRF.","aliases":["CVE-2020-7965","PYSEC-2020-156"],"modified":"2024-11-19T15:49:31.310546Z","published":"2021-04-07T21:06:30Z","database_specific":{"cwe_ids":["CWE-352"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-03-29T22:19:18Z","nvd_published_at":"2020-01-29T15:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7965"},{"type":"WEB","url":"https://github.com/marshmallow-code/webargs/commit/b9ee8b0aa668207a363d9fd21d967eeadb975c3e"},{"type":"PACKAGE","url":"https://github.com/marshmallow-code/webargs"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/webargs/PYSEC-2020-156.yaml"},{"type":"WEB","url":"https://webargs.readthedocs.io/en/latest/changelog.html"},{"type":"WEB","url":"https://webargs.readthedocs.io/en/latest/changelog.html#b4-2020-01-28"},{"type":"WEB","url":"https://webargs.readthedocs.io/en/latest/changelog.html#id11"}],"affected":[{"package":{"name":"webargs","ecosystem":"PyPI","purl":"pkg:pypi/webargs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.5.3"}]}],"versions":["5.0.0","5.1.0","5.1.1","5.1.1.post0","5.1.2","5.1.3","5.2.0","5.3.0","5.3.1","5.3.2","5.4.0","5.5.0","5.5.1","5.5.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-fjq3-5pxw-4wj4/GHSA-fjq3-5pxw-4wj4.json"}},{"package":{"name":"webargs","ecosystem":"PyPI","purl":"pkg:pypi/webargs"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0b1"},{"fixed":"6.0.0b4"}]}],"versions":["6.0.0b1","6.0.0b2","6.0.0b3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-fjq3-5pxw-4wj4/GHSA-fjq3-5pxw-4wj4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}