Back to Database
Status published
High
CVE-2019-14806
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient...
Vulnerability Description
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-14806
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/pallets/werkzeug/blob/7fef41b120327d3912fbe12fb64f1951496fcf3e/src/werkzeug/debug/__init__.py#L168
- https://github.com/pallets/werkzeug/commit/00bc43b1672e662e5e3b8cecd79e67fc968fa246
- https://palletsprojects.com/blog/werkzeug-0-15-3-released/
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00034.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00047.html
More from palletsprojects
View All →CVE-2022-29361
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and...
Critical
9.8
CVE-2020-28724
Open redirect vulnerability in werkzeug before 0.11.6 via a double...
Medium
6.1
CVE-2019-14322
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such...
High
7.5
CVE-2019-10906
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape....
High
8.6
CVE-2018-1000656
The Pallets Project flask version Before 0.12.3 contains a CWE-20:...
High
7.5
Affected Vendor
palletsprojects
View all reports →Affected Software
werkzeug, leap
Vulnerable Versions:
0, 15.0, 15.1
Timeline
Official Publish:
August 9th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.