Insufficient Entropy in Werkzeug - CVE-2019-14806

 

Insufficient Entropy in Werkzeug - CVE-2019-14806

Published: August 9, 2019 / Updated: July 17, 2020


Vulnerability identifier: #VU30827
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14806
CWE-ID: CWE-331
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.


Affected software

Werkzeug
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Opensuse
Ubuntu
python-werkzeug (Ubuntu package)
python3-werkzeug (Ubuntu package)
python-Werkzeug
python3-Werkzeug
IBM Cloud Pak for Data System
SOAR QRadar Plugin App

How to mitigate CVE-2019-14806

Install update from vendor's website.

Werkzeug - update to 0.15.3
python-werkzeug (Ubuntu package) - addressed in versions 0.10.4+dfsg1-1ubuntu1.2, 0.14.1+dfsg1-1ubuntu0.1
python3-werkzeug (Ubuntu package) - addressed in versions 0.10.4+dfsg1-1ubuntu1.2, 0.14.1+dfsg1-1ubuntu0.1
python-Werkzeug - update to 0.12.2-10.10.1
python3-Werkzeug - update to 0.12.2-10.10.1
IBM Cloud Pak for Data System - update to 2.0.2.1.IF1
SOAR QRadar Plugin App - update to 5.0.3

External References

Related Security Bulletins