Логотип exploitDog
bind:"CVE-2024-49767"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-49767"

Количество 9

Количество 9

ubuntu логотип

CVE-2024-49767

около 1 года назад

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds. Werkzeug version 3.0.6 fixes this issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-49767

около 1 года назад

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds. Werkzeug version 3.0.6 fixes this issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-49767

около 1 года назад

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds. Werkzeug version 3.0.6 fixes this issue.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-49767

около 1 года назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-49767

около 1 года назад

Werkzeug is a Web Server Gateway Interface web application library. Ap ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3810-1

около 1 года назад

Security update for python-Werkzeug

EPSS: Низкий
github логотип

GHSA-q34m-jh98-gwm2

около 1 года назад

Werkzeug possible resource exhaustion when parsing file data in forms

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2025-06972

около 1 года назад

Уязвимость библиотеки веб-приложений Pallets Werkzeug, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20251229-7301

16 дней назад

Уязвимость python-werkzeug

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-49767

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds. Werkzeug version 3.0.6 fixes this issue.

CVSS3: 7.5
1%
Низкий
около 1 года назад
redhat логотип
CVE-2024-49767

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds. Werkzeug version 3.0.6 fixes this issue.

CVSS3: 5.3
1%
Низкий
около 1 года назад
nvd логотип
CVE-2024-49767

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parse `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A specifically crafted form submission request can cause the parser to allocate and block 3 to 8 times the upload size in main memory. There is no upper limit; a single upload at 1 Gbit/s can exhaust 32 GB of RAM in less than 60 seconds. Werkzeug version 3.0.6 fixes this issue.

CVSS3: 7.5
1%
Низкий
около 1 года назад
msrc логотип
CVSS3: 7.5
1%
Низкий
около 1 года назад
debian логотип
CVE-2024-49767

Werkzeug is a Web Server Gateway Interface web application library. Ap ...

CVSS3: 7.5
1%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3810-1

Security update for python-Werkzeug

1%
Низкий
около 1 года назад
github логотип
GHSA-q34m-jh98-gwm2

Werkzeug possible resource exhaustion when parsing file data in forms

CVSS3: 7.5
1%
Низкий
около 1 года назад
fstec логотип
BDU:2025-06972

Уязвимость библиотеки веб-приложений Pallets Werkzeug, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
около 1 года назад
redos логотип
ROS-20251229-7301

Уязвимость python-werkzeug

CVSS3: 7.5
1%
Низкий
16 дней назад

Уязвимостей на страницу