You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
…and 1 more
Security information
Factors contributing to the scoring:
Snyk: [CVSS 7.5](https://security.snyk.io/vuln/SNYK-PYTHON-WERKZEUG-6808933) - High Severity
NVD: Not available. NVD has not yet published its analysis.
Why are the scores different? Learn how Snyk evaluates vulnerability scores
Overview
Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to insufficient hostname checks and the use of relative paths to resolve requests. When the debugger is enabled, an attacker can convince a user to enter their own PIN to interact with a domain and subdomain they control, and thereby cause malicious code to be executed.
The demonstrated attack vector requires a number of conditions that render this attack very difficult to achieve, especially if the victim application is running in the recommended configuration of not having the debugger enabled in production.
Completion Criteria
We have either determined this is not a risk and ignored the flag or vuln is remediated
The text was updated successfully, but these errors were encountered:
Introduced through
[email protected]
Fixed in
[email protected]
Detailed paths and remediation
Introduced through: [email protected] › [email protected] › [email protected] › [email protected]
Fix: Pin werkzeug to version 3.0.3
Introduced through: [email protected] › [email protected] › [email protected] › [email protected] › [email protected]
Fix: Pin werkzeug to version 3.0.3
…and 1 more
Security information
Factors contributing to the scoring:
Why are the scores different? Learn how Snyk evaluates vulnerability scores
Overview
Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to insufficient hostname checks and the use of relative paths to resolve requests. When the debugger is enabled, an attacker can convince a user to enter their own PIN to interact with a domain and subdomain they control, and thereby cause malicious code to be executed.
The demonstrated attack vector requires a number of conditions that render this attack very difficult to achieve, especially if the victim application is running in the recommended configuration of not having the debugger enabled in production.
Completion Criteria
The text was updated successfully, but these errors were encountered: