CVE-2019-14806

EUVD-2019-0160
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
Affected Products (NVD)
VendorProductVersion
palletsprojectswerkzeug
𝑥
< 0.15.3
opensuseleap
15.0
opensuseleap
15.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-werkzeug
bookworm
2.2.2-3
fixed
bullseye
1.0.1+dfsg1-2+deb11u1
fixed
bullseye (security)
1.0.1+dfsg1-2+deb11u1
fixed
jessie
not-affected
sid
3.0.4-1
fixed
trixie
3.0.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-werkzeug
bionic
Fixed 0.14.1+dfsg1-1ubuntu0.1
released
disco
ignored
eoan
ignored
focal
not-affected
groovy
not-affected
trusty
dne
xenial
not-affected