Inefficient Algorithmic Complexity in Werkzeug - CVE-2023-46136

 

Inefficient Algorithmic Complexity in Werkzeug - CVE-2023-46136

Published: October 30, 2023


Vulnerability identifier: #VU82548
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46136
CWE-ID: CWE-407
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to high resource usage when parsing multipart/form-data. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

Werkzeug
watsonx.data
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
Python 3 Module
openSUSE Leap
openEuler
IBM Concert Software
IBM Cloud Pak for Data System
Oracle Communications Network Analytics Data Director
Oracle Communications Cloud Native Core Binding Support Function
Oracle Communications Cloud Native Core Automated Test Suite
Oracle Communications Cloud Native Core Network Repository Function
IBM Process Mining
Qradar Advisor
IBM Fusion HCI
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Maximo Application Suite
IBM Spectrum Protect Plus
QRadar Suite
Juniper Secure Analytics (JSA)
IBM Cloud Pak for Multicloud Management
Red Hat OpenShift Container Platform
Oracle Communications Operations Monitor
Storage Ceph
Maximo Application Suite - Visual Inspection Component
Storage Sentinel Anomaly Scan Engine
QRadar Assistant
IBM Cloud Pak for Watson AIOps
SOAR QRadar Plugin App
IBM QRadar Incident Forensics
Maximo Application Suite - Monitor Component
IBM Qradar SIEM
Cloud Pak for Data
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
python-eventlet (Red Hat package)
cri-o (Red Hat package)
python-werkzeug (Red Hat package)
python-werkzeug
python-werkzeug-help
python3-werkzeug
python-markupsafe (Red Hat package)
python311-Werkzeug
oath-toolkit (Red Hat package)
haproxy (Red Hat package)
cephadm-ansible (Red Hat package)
openshift (Red Hat package)
openshift-clients (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
ceph (Red Hat package)
Red Hat Ceph Storage
IBM InfoSphere Information Server

How to mitigate CVE-2023-46136

Install updates from vendor's website.

Werkzeug - update to 3.0.1
IBM Concert Software - update to 1.0.3
QRadar Suite - update to 1.10.21.0
IBM Cloud Pak for Data System - update to 2.0.2.1.IF2
watsonx.data - update to 2.3.1
IBM Cloud Pak for Multicloud Management - update to 2.3.8
Red Hat OpenShift Container Platform - addressed in versions 4.12.45, 4.13.24
Storage Ceph - update to 8.1
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
Maximo Application Suite - Visual Inspection Component - update to 9.0.2
python-eventlet (Red Hat package) - update to 0.33.1-5.el9
Storage Sentinel Anomaly Scan Engine - update to 1.1.7
IBM Process Mining - update to 1.14.3
cri-o (Red Hat package) - addressed in versions 1.25.5-2.rhaos4.12.git0217273.el8, 1.27.2-2.rhaos4.14.git9d684e2.el8, 1.27.2-2.rhaos4.14.git9d684e2.el9
python-werkzeug (Red Hat package) - addressed in versions 2.0.3-5.el9, 2.2.3-2.el9
python-werkzeug - addressed in versions 2.0.3-6, 2.2.3-4
python-werkzeug-help - addressed in versions 2.0.3-6, 2.2.3-4
python3-werkzeug - addressed in versions 2.0.3-6, 2.2.3-4
python-markupsafe (Red Hat package) - update to 2.1.1-4.el9
python311-Werkzeug - update to 2.3.6-150400.6.6.1
Qradar Advisor - update to 2.6.6
oath-toolkit (Red Hat package) - update to 2.6.12-1.el9cp
haproxy (Red Hat package) - update to 2.6.13-2.rhaos4.14.el8
IBM Fusion HCI - update to 2.7.1
QRadar Assistant - update to 3.7.0
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
IBM Cloud Pak for Watson AIOps - update to 4.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.2
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.2
Cloud Pak for Data - update to 4.8.5
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
openshift (Red Hat package) - addressed in versions 4.12.0-202311161331.p0.ga52e8df.assembly.stream.el8, 4.12.0-202311161331.p0.ga52e8df.assembly.stream.el9, 4.13.0-202311212009.p0.gaa37255.assembly.stream.el8, 4.13.0-202311212009.p0.gaa37255.assembly.stream.el9, 4.14.0-202311161233.p0.gd548052.assembly.stream.el8, 4.14.0-202311161233.p0.gd548052.assembly.stream.el9
openshift-clients (Red Hat package) - addressed in versions 4.12.0-202311221849.p0.gd2ac7e1.assembly.stream.el8, 4.12.0-202311221849.p0.gd2ac7e1.assembly.stream.el9
kernel (Red Hat package) - update to 4.18.0-372.82.1.el8_6
kernel-rt (Red Hat package) - update to 4.18.0-372.82.1.rt7.241.el8_6
SOAR QRadar Plugin App - update to 5.3.1
IBM QRadar Incident Forensics - update to 7.5.0.10
Red Hat Ceph Storage - update to 8.1
IBM Maximo Application Suite - addressed in versions 8.7.7, 8.10.8
Maximo Application Suite - Monitor Component - addressed in versions 8.10.13, 8.11.13, 9.0.5, 9.1.0
IBM Spectrum Protect Plus - update to 10.1.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
ceph (Red Hat package) - update to 19.2.1-222.el9cp

External References

Related Security Bulletins