← All CVEs NewScan detects
high

CVE-2023-30861

Flask session cookie can be cached by a proxy and served to another client (session disclosure)

Severity
high
Affected product
Flask
Affected versions
Flask < 2.2.5
Fixed in
Flask 2.2.5 / 2.3.2
Added to NewScan
2026-08-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Flask from its response and reports this CVE when the detected version falls inside the affected range below.

Also affects 2.3.0-2.3.1, which the 2.2.5 boundary does not cover; a second row would be needed if 2.3.x builds are still in the wild.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →