Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-werkzeug | Jul 30, 2024 | Aug 9, 2019 |
| Suse | — | Upgrade python-Werkzeug-docUpgrade python2-WerkzeugUpgrade python3-Werkzeug | Sep 11, 2019 | Aug 9, 2019 |
| Ubuntu | — | Upgrade python-werkzeugUpgrade python3-werkzeug | Dec 2, 2020 | Aug 9, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub