Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14806

Опубликовано: 09 авг. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

Отчет

While Red Hat Quay contains a vulnerable version of python-werkzeug in the quay container image, use of the debug feature is not recommended in any upstream or downstream documentation. A user of Red Hat Quay would have to enable python-werkzeug debugging before Red Hat Quay became vulnerable. This issue did not affect the versions of python-werkzeug as shipped with Red Hat Update Infrastructure as they did not include support for PIN based authentication. The same is true for the versions of python-werkzeug as shipped with Red Hat Enterprise Linux 8. Red Hat Satellite ships vulnerable python-werkzeug, however, it is not affected because it uses python-werkzeug as a dependency of python-flask required by Crane component and therefore package does not get invoked directly.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 2python-werkzeugNot affected
Red Hat Enterprise Linux 8python-werkzeugNot affected
Red Hat OpenStack Platform 14 (Rocky)python-werkzeugOut of support scope
Red Hat OpenStack Platform 15 (Stein)python-werkzeugOut of support scope
Red Hat Quay 3quayNot affected
Red Hat Satellite 6python-werkzeugWill not fix
Red Hat Storage 3python-werkzeugNot affected
Red Hat Update Infrastructure 3 for Cloud Providerspython-werkzeugNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-330
https://bugzilla.redhat.com/show_bug.cgi?id=1771359python-werkzeug: insufficient debugger PIN randomness vulnerability

EPSS

Процентиль: 50%
0.00264
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

CVSS3: 7.5
nvd
больше 6 лет назад

Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

CVSS3: 7.5
debian
больше 6 лет назад

Pallets Werkzeug before 0.15.3, when used with Docker, has insufficien ...

suse-cvrf
больше 6 лет назад

Security update for python-Werkzeug

suse-cvrf
больше 6 лет назад

Security update for python-Werkzeug

EPSS

Процентиль: 50%
0.00264
Низкий

7.5 High

CVSS3