prefect is vulnerable to Authentication Bypass Using an Alternate Path or Channel
63
Medium Risk
Affected versions of this package are affected by an authentication bypass vulnerability due to improper path validation when exempting health check endpoints from authentication. The implementation uses a suffix-based check (e.g., endswith) to determine whether a request should bypass authentication, allowing crafted request paths that end with the expected suffix to incorrectly skip authentication. An attacker could exploit this by accessing protected endpoints using specially crafted URLs that match the suffix condition. The issue is addressed by enforcing strict validation of allowed paths when applying authentication exemptions.
You are affected if you are using a version that falls within the vulnerable range.
prefect is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 3.2.7 - 3.6.21.
Upgrade the prefect library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant