Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-49766

Опубликовано: 25 окт. 2024
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially allowing unintended access to data. Applications using Python >= 3.11, or not using Windows, are not vulnerable. Werkzeug version 3.0.6 contains a patch.

A flaw was found in Werkzeug. In Python versions below v3.11 on Windows, os.path.isabs() does not catch UNC paths such as //server/share. Werkzeug's safe_join() relies on this check and can produce a path that is not safe, which can allow unintended access to data.

Отчет

Red Hat is not affected by this vulnerability, as it is specific to applications using certain versions of Python on Windows.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2python3.11-werkzeugNot affected
Red Hat Ceph Storage 5python-werkzeugNot affected
Red Hat Ceph Storage 6python-werkzeugNot affected
Red Hat Ceph Storage 7python-werkzeugNot affected
Red Hat Enterprise Linux 8python-werkzeugNot affected
Red Hat OpenShift Container Platform 4python-werkzeugNot affected
Red Hat OpenStack Platform 16.2python-werkzeugNot affected
Red Hat OpenStack Platform 17.1python-werkzeugNot affected
Red Hat Quay 3quay/quay-rhel8Not affected
Red Hat Storage 3python-werkzeugNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2321828werkzeug: python-werkzeug: Werkzeug safe_join not safe on Windows

EPSS

Процентиль: 73%
0.00786
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 года назад

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially allowing unintended access to data. Applications using Python >= 3.11, or not using Windows, are not vulnerable. Werkzeug version 3.0.6 contains a patch.

CVSS3: 5.3
nvd
около 1 года назад

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially allowing unintended access to data. Applications using Python >= 3.11, or not using Windows, are not vulnerable. Werkzeug version 3.0.6 contains a patch.

CVSS3: 5.3
debian
около 1 года назад

Werkzeug is a Web Server Gateway Interface web application library. On ...

github
около 1 года назад

Werkzeug safe_join not safe on Windows

EPSS

Процентиль: 73%
0.00786
Низкий

3.7 Low

CVSS3