Input validation error in Werkzeug - CVE-2023-23934

 

Input validation error in Werkzeug - CVE-2023-23934

Published: February 16, 2023


Vulnerability identifier: #VU72340
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-23934
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient validation of "nameless" cookies. A remote attacker can manipulate cookie values for an arbitrary domain.


Affected software

Werkzeug
watsonx.data
Amazon Linux AMI
Debian Linux
Fedora
Anolis OS
Ubuntu
openEuler
IBM Cloud Pak for Watson AIOps
Storage Ceph
Storage Sentinel Anomaly Scan Engine
QRadar Assistant
SOAR QRadar Plugin App
IBM QRadar Incident Forensics
Robotic Process Automation for Cloud Pak
IBM Cloud Pak for Data System
Qradar Advisor
Spectrum Discover
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Elastic Storage System
IBM Maximo Application Suite
IBM Spectrum Protect Plus
IBM Cloud Pak for Multicloud Management
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Cloud Pak for Security (CP4S)
python3-werkzeug (Ubuntu package)
python-werkzeug (Ubuntu package)
python3-werkzeug
python-werkzeug-doc
python-werkzeug (Debian package)
python3-werkzeug-doc
python-werkzeug
python2-werkzeug
mingw-python-werkzeug
oath-toolkit (Red Hat package)
cephadm-ansible (Red Hat package)
ceph (Red Hat package)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Ceph Storage

How to mitigate CVE-2023-23934

Install updates from vendor's website.

Werkzeug - update to 2.2.3
IBM Cloud Pak for Data System - update to 1.0.8.0
IBM Cloud Pak for Multicloud Management - update to 2.3.8
watsonx.data - update to 2.3.1
Qradar Advisor - update to 2.6.5
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
Storage Ceph - update to 8.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
python3-werkzeug (Ubuntu package) - addressed in versions Ubuntu Pro, 0.14.1+dfsg1-1ubuntu0.2, 0.16.1+dfsg1-2ubuntu0.1, 2.0.2+dfsg1-1ubuntu0.22.04.1, 2.0.2+dfsg1-3ubuntu0.22.10.1, 2.2.2-2ubuntu0.1
python-werkzeug (Ubuntu package) - addressed in versions Ubuntu Pro, 0.14.1+dfsg1-1ubuntu0.2
python3-werkzeug - update to 0.12.2-7
python-werkzeug-doc - update to 0.12.2-7
python-werkzeug (Debian package) - update to 1.0.1+dfsg1-2+deb11u1
python3-werkzeug-doc - update to 1.0.1-2
python-werkzeug - update to 1.0.1-2
python3-werkzeug - update to 1.0.1-2
python2-werkzeug - update to 1.0.1-2
python3-werkzeug - update to 1.0.1-2.el7
python-werkzeug - update to 1.0.1-5
Storage Sentinel Anomaly Scan Engine - update to 1.1.4.1
Cloud Pak for Security (CP4S) - update to 1.10.12.0
Spectrum Discover - addressed in versions 2.0.4.8, 2.1.1
mingw-python-werkzeug - addressed in versions 2.2.3-1.fc37, 2.2.3-1.fc38
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el8cp, 2.6.12-1.el9cp
QRadar Assistant - update to 3.7.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.6.3
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.7
SOAR QRadar Plugin App - update to 5.0.3
IBM Elastic Storage System - update to 6.1.8.1
Red Hat Ceph Storage - addressed in versions 7.1, 8.1
IBM QRadar Incident Forensics - update to 7.5.0.10
IBM Maximo Application Suite - addressed in versions 8.8.8, 8.9.4, 8.10.1
IBM Spectrum Protect Plus - update to 10.1.15
ceph (Red Hat package) - addressed in versions 18.2.1-329.el8cp, 18.2.1-329.el9cp, 19.2.1-222.el9cp
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.3, 23.0.3

External References

Related Security Bulletins