Input validation error in Werkzeug - CVE-2023-23934
Published: February 16, 2023
Vulnerability identifier: #VU72340
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23934
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient validation of "nameless" cookies. A remote attacker can manipulate cookie values for an arbitrary domain.
Affected software
Werkzeug
watsonx.data
Amazon Linux AMI
Debian Linux
Fedora
Anolis OS
Ubuntu
openEuler
IBM Cloud Pak for Watson AIOps
Storage Ceph
Storage Sentinel Anomaly Scan Engine
QRadar Assistant
SOAR QRadar Plugin App
IBM QRadar Incident Forensics
Robotic Process Automation for Cloud Pak
IBM Cloud Pak for Data System
Qradar Advisor
Spectrum Discover
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Elastic Storage System
IBM Maximo Application Suite
IBM Spectrum Protect Plus
IBM Cloud Pak for Multicloud Management
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
python3-werkzeug (Ubuntu package)
python-werkzeug (Ubuntu package)
python3-werkzeug
python-werkzeug-doc
python-werkzeug (Debian package)
python3-werkzeug-doc
python-werkzeug
python2-werkzeug
mingw-python-werkzeug
oath-toolkit (Red Hat package)
cephadm-ansible (Red Hat package)
ceph (Red Hat package)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Ceph Storage
watsonx.data
Amazon Linux AMI
Debian Linux
Fedora
Anolis OS
Ubuntu
openEuler
IBM Cloud Pak for Watson AIOps
Storage Ceph
Storage Sentinel Anomaly Scan Engine
QRadar Assistant
SOAR QRadar Plugin App
IBM QRadar Incident Forensics
Robotic Process Automation for Cloud Pak
IBM Cloud Pak for Data System
Qradar Advisor
Spectrum Discover
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Elastic Storage System
IBM Maximo Application Suite
IBM Spectrum Protect Plus
IBM Cloud Pak for Multicloud Management
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
python3-werkzeug (Ubuntu package)
python-werkzeug (Ubuntu package)
python3-werkzeug
python-werkzeug-doc
python-werkzeug (Debian package)
python3-werkzeug-doc
python-werkzeug
python2-werkzeug
mingw-python-werkzeug
oath-toolkit (Red Hat package)
cephadm-ansible (Red Hat package)
ceph (Red Hat package)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Ceph Storage
How to mitigate CVE-2023-23934
Install updates from vendor's website.
Werkzeug - update to 2.2.3
IBM Cloud Pak for Data System - update to 1.0.8.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
watsonx.data - update to 2.3.1
Qradar Advisor - update to 2.6.5
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Storage Ceph - update to 8.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
python3-werkzeug (Ubuntu package) - addressed in versions Ubuntu Pro, 0.14.1+dfsg1-1ubuntu0.2, 0.16.1+dfsg1-2ubuntu0.1, 2.0.2+dfsg1-1ubuntu0.22.04.1, 2.0.2+dfsg1-3ubuntu0.22.10.1, 2.2.2-2ubuntu0.1
python-werkzeug (Ubuntu package) - addressed in versions Ubuntu Pro, 0.14.1+dfsg1-1ubuntu0.2
python3-werkzeug - update to 0.12.2-7
python-werkzeug-doc - update to 0.12.2-7
python-werkzeug (Debian package) - update to 1.0.1+dfsg1-2+deb11u1
python3-werkzeug-doc - update to 1.0.1-2
python-werkzeug - update to 1.0.1-2
python3-werkzeug - update to 1.0.1-2
python2-werkzeug - update to 1.0.1-2
python3-werkzeug - update to 1.0.1-2.el7
python-werkzeug - update to 1.0.1-5
Storage Sentinel Anomaly Scan Engine - update to 1.1.4.1
Cloud Pak for Security (CP4S) - update to 1.10.12.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
mingw-python-werkzeug - addressed in versions 2.2.3-1.fc37, 2.2.3-1.fc38
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el8cp, 2.6.12-1.el9cp
QRadar Assistant - update to 3.7.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.3
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7
SOAR QRadar Plugin App - update to 5.0.3
IBM Elastic Storage System - update to 6.1.8.1
Red Hat Ceph Storage - addressed in versions 7.1, 8.1
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Maximo Application Suite - addressed in versions 8.8.8, 8.9.4, 8.10.1
IBM Spectrum Protect Plus - update to 10.1.15
ceph (Red Hat package) - addressed in versions 18.2.1-329.el8cp, 18.2.1-329.el9cp, 19.2.1-222.el9cp
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3
IBM Cloud Pak for Data System - update to 1.0.8.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
watsonx.data - update to 2.3.1
Qradar Advisor - update to 2.6.5
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Storage Ceph - update to 8.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
python3-werkzeug (Ubuntu package) - addressed in versions Ubuntu Pro, 0.14.1+dfsg1-1ubuntu0.2, 0.16.1+dfsg1-2ubuntu0.1, 2.0.2+dfsg1-1ubuntu0.22.04.1, 2.0.2+dfsg1-3ubuntu0.22.10.1, 2.2.2-2ubuntu0.1
python-werkzeug (Ubuntu package) - addressed in versions Ubuntu Pro, 0.14.1+dfsg1-1ubuntu0.2
python3-werkzeug - update to 0.12.2-7
python-werkzeug-doc - update to 0.12.2-7
python-werkzeug (Debian package) - update to 1.0.1+dfsg1-2+deb11u1
python3-werkzeug-doc - update to 1.0.1-2
python-werkzeug - update to 1.0.1-2
python3-werkzeug - update to 1.0.1-2
python2-werkzeug - update to 1.0.1-2
python3-werkzeug - update to 1.0.1-2.el7
python-werkzeug - update to 1.0.1-5
Storage Sentinel Anomaly Scan Engine - update to 1.1.4.1
Cloud Pak for Security (CP4S) - update to 1.10.12.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
mingw-python-werkzeug - addressed in versions 2.2.3-1.fc37, 2.2.3-1.fc38
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el8cp, 2.6.12-1.el9cp
QRadar Assistant - update to 3.7.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.3
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7
SOAR QRadar Plugin App - update to 5.0.3
IBM Elastic Storage System - update to 6.1.8.1
Red Hat Ceph Storage - addressed in versions 7.1, 8.1
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Maximo Application Suite - addressed in versions 8.8.8, 8.9.4, 8.10.1
IBM Spectrum Protect Plus - update to 10.1.15
ceph (Red Hat package) - addressed in versions 18.2.1-329.el8cp, 18.2.1-329.el9cp, 19.2.1-222.el9cp
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3
External References
Related Security Bulletins
- Multiple vulnerabilities in Werkzeug
- Ubuntu update for python-werkzeug
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in IBM Cloud Pak for Data System
- Multiple vulnerabilities in IBM Watson Discovery Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Advisor With Watson App for IBM QRadar SIEM
- Multiple vulnerabilities in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in IBM Spectrum Protect Plus File Systems Agent
- Ubuntu update for python-werkzeug
- Multiple vulnerabilities in IBM Spectrum Discover
- Input validation error in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Spectrum Sentinel Anomaly Scan Engine
- Debian update for python-werkzeug
- Multiple vulnerabilities in IBM Elastic Storage System
- Fedora 38 update for mingw-python-werkzeug
- Fedora 37 update for mingw-python-werkzeug
- Fedora EPEL 7 update for python3-werkzeug
- Multiple vulnerabilities in IBM SOAR QRadar Plugin App
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- openEuler update for python-werkzeug
- Multiple vulnerabilities in IBM QRadar Assistant
- Amazon Linux AMI update for python-werkzeug
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics
- Anolis OS update for python-werkzeug
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Dell RecoverPoint for Virtual Machines update for third-party components
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- Multiple vulnerabilities in IBM Storage Ceph
- Multiple vulnerabilities in IBM watsonx.data