CVE-2023-29005: Dpgaspar Flask-Appbuilder

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`, and setting an `AUTH_RATE_LIMIT`.

Affected products

  • Dpgaspar Flask-Appbuilder: before 4.3.0 (fixed in 4.3.0)

Published 2023-04-10. Last modified 2026-06-17.