Описание
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 1.3 | python-werkzeug | Will not fix | ||
| Red Hat Ceph Storage 2 | python-werkzeug | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | python-werkzeug | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | python-werkzeug | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-werkzeug | Will not fix | ||
| Red Hat Software Collections | python27-python-werkzeug | Will not fix | ||
| Red Hat Satellite 6.6 for RHEL 7 | ansiblerole-foreman_scap_client | Fixed | RHSA-2019:3172 | 22.10.2019 |
| Red Hat Satellite 6.6 for RHEL 7 | ansiblerole-insights-client | Fixed | RHSA-2019:3172 | 22.10.2019 |
| Red Hat Satellite 6.6 for RHEL 7 | ansible-runner | Fixed | RHSA-2019:3172 | 22.10.2019 |
| Red Hat Satellite 6.6 for RHEL 7 | candlepin | Fixed | RHSA-2019:3172 | 22.10.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
Cross-site scripting (XSS) vulnerability in the render_full function i ...
Pallets Werkzeug cross-site scripting vulnerability
EPSS
7.1 High
CVSS3