CVE-2019-14806Insufficient Entropy in Werkzeug

Severity
7.5HIGHNVD
EPSS
0.3%
top 50.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 9
Latest updateDec 1

Description

Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDopensuse/leap15.0, 15.1+1

Patches

🔴Vulnerability Details

5
OSV
python-werkzeug vulnerabilities2020-12-01
OSV
Pallets Werkzeug Insufficient Entropy2019-08-21
GHSA
Pallets Werkzeug Insufficient Entropy2019-08-21
CVEList
CVE-2019-14806: Pallets Werkzeug before 02019-08-09
OSV
CVE-2019-14806: Pallets Werkzeug before 02019-08-09

📋Vendor Advisories

3
Ubuntu
Werkzeug vulnerabilities2020-12-01
Red Hat
python-werkzeug: insufficient debugger PIN randomness vulnerability2019-08-09
Debian
CVE-2019-14806: python-werkzeug - Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger...2019

💬Community

4
Bugzilla
CVE-2019-14806 python-werkzeug: insufficient debugger PIN randomness vulnerability [openstack-rdo]2019-11-13
Bugzilla
CVE-2019-14806 python-werkzeug: insufficient debugger PIN randomness vulnerability2019-11-12
Bugzilla
CVE-2019-14806 python-werkzeug: insufficient debugger PIN randomness vulnerability [epel-6]2019-11-12
Bugzilla
CVE-2019-14806 python-werkzeug: insufficient debugger PIN randomness vulnerability [fedora-all]2019-11-12
CVE-2019-14806 — Insufficient Entropy in Werkzeug | cvebase