USN-6799-1: Werkzeug vulnerability
29 May 2024
Werkzeug could be made to execute code under certain circumstances.
Releases
Packages
- python-werkzeug - collection of utilities for WSGI applications
Details
It was discovered that the debugger in Werkzeug was not restricted to
trusted hosts. A remote attacker could possibly use this issue to execute
code on the host under certain circumstances.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
Ubuntu 23.10
Ubuntu 22.04
Ubuntu 20.04
Ubuntu 18.04
-
python-werkzeug
-
0.14.1+dfsg1-1ubuntu0.2+esm1
Available with Ubuntu Pro
-
python3-werkzeug
-
0.14.1+dfsg1-1ubuntu0.2+esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
python-werkzeug
-
0.10.4+dfsg1-1ubuntu1.2+esm2
Available with Ubuntu Pro
-
python3-werkzeug
-
0.10.4+dfsg1-1ubuntu1.2+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.