Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-10516

Опубликовано: 23 окт. 2017
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3python-werkzeugWill not fix
Red Hat Ceph Storage 2python-werkzeugWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)python-werkzeugWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installerpython-werkzeugWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)python-werkzeugWill not fix
Red Hat Software Collectionspython27-python-werkzeugWill not fix
Red Hat Satellite 6.6 for RHEL 7ansiblerole-foreman_scap_clientFixedRHSA-2019:317222.10.2019
Red Hat Satellite 6.6 for RHEL 7ansiblerole-insights-clientFixedRHSA-2019:317222.10.2019
Red Hat Satellite 6.6 for RHEL 7ansible-runnerFixedRHSA-2019:317222.10.2019
Red Hat Satellite 6.6 for RHEL 7candlepinFixedRHSA-2019:317222.10.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1512102python-werkzeug: Cross-site scripting in render_full function in debug/tbtools.py

EPSS

Процентиль: 54%
0.00314
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

CVSS3: 6.1
nvd
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.

CVSS3: 6.1
debian
больше 8 лет назад

Cross-site scripting (XSS) vulnerability in the render_full function i ...

CVSS3: 6.1
github
больше 3 лет назад

Pallets Werkzeug cross-site scripting vulnerability

EPSS

Процентиль: 54%
0.00314
Низкий

7.1 High

CVSS3

Уязвимость CVE-2016-10516