CVE-2024-49766Path Traversal in Werkzeug

CWE-22Path Traversal8 documents7 sources
Severity
6.3MEDIUMNVD
EPSS
1.4%
top 19.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateJan 15

Description

Werkzeug is a Web Server Gateway Interface web application library. On Python = 3.11, or not using Windows, are not vulnerable. Werkzeug version 3.0.6 contains a patch.

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages3 packages

CVEListV5pallets/werkzeug< 3.0.6

Patches

🔴Vulnerability Details

4
OSV
CVE-2024-49766: Werkzeug is a Web Server Gateway Interface web application library2024-10-28
OSV
Werkzeug safe_join not safe on Windows2024-10-25
GHSA
Werkzeug safe_join not safe on Windows2024-10-25
CVEList
Werkzeug safe_join not safe on Windows2024-10-25

📋Vendor Advisories

3
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Werkzeug) — CVE-2024-497662025-01-15
Red Hat
werkzeug: python-werkzeug: Werkzeug safe_join not safe on Windows2024-10-25
Debian
CVE-2024-49766: python-werkzeug - Werkzeug is a Web Server Gateway Interface web application library. On Python < ...2024
CVE-2024-49766 — Path Traversal in Pallets Werkzeug | cvebase