CVE-2024-49766
25.10.2024, 20:15
Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially allowing unintended access to data. Applications using Python >= 3.11, or not using Windows, are not vulnerable. Werkzeug version 3.0.6 contains a patch.
| Vendor | Product | Version |
|---|---|---|
| palletsprojects | werkzeug | 𝑥 < 3.0.6 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases