Code Injection in Werkzeug - CVE-2024-34069
Published: May 6, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation within the debugger. A remote attacker can trick the developer to interact with a domain and subdomain they control and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
watsonx.data
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Enterprise Storage
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Python 3 Module
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Fedora
IBM Concert Software
IBM Process Mining
IBM Spectrum Protect Plus
Qradar Advisor
QRadar User Behavior Analytics
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Maximo Application Suite
Red Hat OpenStack
QRadar Suite
Cloud Pak for Data
IBM Qradar SIEM
Storage Ceph
Security QRadar EDR
IBM Cloud Pak for Watson AIOps
IBM Watson Machine Learning Accelerator
watsonx Assistant Cartridge
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Maximo Application Suite - Monitor Component
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
python-werkzeug (Ubuntu package)
python3-werkzeug (Ubuntu package)
python-Werkzeug
python3-Werkzeug
python-werkzeug (Red Hat package)
python-Werkzeug-doc
python3-werkzeug
python3-werkzeug-doc
python2-werkzeug
python-werkzeug
python2-Werkzeug
cri-o (Red Hat package)
python-werkzeug-help
mingw-python-werkzeug
python311-Werkzeug
oath-toolkit (Red Hat package)
openshift (Red Hat package)
openshift-ansible (Red Hat package)
kernel-rt (Red Hat package)
kernel (Red Hat package)
ceph (Red Hat package)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat OpenShift Container Platform
Red Hat Ceph Storage
How to mitigate CVE-2024-34069
IBM Concert Software - update to 1.0.3
QRadar Suite - update to 1.10.25.0
IBM Process Mining - update to 1.15.0
watsonx.data - update to 2.3.1
Cloud Pak for Data - update to 5.2
Storage Ceph - update to 8.1
IBM Spectrum Protect Plus - update to 10.1.17.1
python-werkzeug (Ubuntu package) - update to Ubuntu Pro
python3-werkzeug (Ubuntu package) - addressed in versions Ubuntu Pro, 0.16.1+dfsg1-2ubuntu0.2, 2.0.2+dfsg1-1ubuntu0.22.04.2, 2.2.2-3ubuntu0.1, 3.0.1-3ubuntu0.1
python-Werkzeug - update to 0.12.2-10.16.1
python3-Werkzeug - addressed in versions 0.12.2-10.16.1, 0.14.1-150100.6.9.1, 1.0.1-150300.3.8.1
python-werkzeug (Red Hat package) - addressed in versions 0.14.1-13.el8ost, 2.0.1-7.el9ost, 2.0.1-9.el8ost, 2.0.3-6.el9, 2.2.3-3.el9
python-Werkzeug-doc - update to 0.14.1-150100.6.9.1
python3-werkzeug - addressed in versions 1.0.1-3, 2.0.3-6
python3-werkzeug-doc - update to 1.0.1-3
python2-werkzeug - update to 1.0.1-3
python-werkzeug - addressed in versions 1.0.1-3, 2.0.3-6
python2-Werkzeug - update to 1.0.1-150300.3.8.1
cri-o (Red Hat package) - update to 1.25.5-26.rhaos4.12.git635413a.el8
python-werkzeug-help - update to 2.0.3-6
mingw-python-werkzeug - addressed in versions 2.2.3-2.fc38, 3.0.3-1.fc40
python311-Werkzeug - update to 2.3.6-150400.6.9.1
Qradar Advisor - update to 2.6.6
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el8cp, 2.6.12-1.el9cp
python3-werkzeug-doc - update to 3.0.1-3
python3-werkzeug - update to 3.0.1-3
Security QRadar EDR - update to 3.12.9
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14
QRadar User Behavior Analytics - update to 4.1.17
IBM Cloud Pak for Watson AIOps - update to 4.6.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1
openshift (Red Hat package) - addressed in versions 4.12.0-202408131833.p0.g1eb8682.assembly.stream.el8, 4.12.0-202408131833.p0.g1eb8682.assembly.stream.el9, 4.15.0-202408271137.p0.g0c3c368.assembly.stream.el8, 4.15.0-202408271137.p0.g0c3c368.assembly.stream.el9
Red Hat OpenShift Container Platform - addressed in versions 4.12.64, 4.15.30, 4.16.7
openshift-ansible (Red Hat package) - addressed in versions 4.15.0-202408281508.p0.g330394a.assembly.stream.el8, 4.15.0-202408281508.p0.g330394a.assembly.stream.el9
kernel-rt (Red Hat package) - update to 4.18.0-372.119.1.rt7.279.el8_6
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0.1
IBM Watson Machine Learning Accelerator - update to 5.0.3
watsonx Assistant Cartridge - update to 5.1.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
kernel (Red Hat package) - update to 5.14.0-284.82.1.el9_2
Red Hat Ceph Storage - update to 7.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
Maximo Application Suite - Monitor Component - addressed in versions 8.10.13, 8.11.13, 9.0.5, 9.1.0
IBM Maximo Application Suite - addressed in versions 8.10.16, 8.11.13, 9.0.1
Red Hat OpenStack - addressed in versions 16.2, 17.1.4
ceph (Red Hat package) - addressed in versions 18.2.1-329.el8cp, 18.2.1-329.el9cp
External References
Related Security Bulletins
- Remote code execution in Werkzeug
- Fedora 40 update for mingw-python-werkzeug
- SUSE update for python-Werkzeug
- SUSE update for python-Werkzeug
- Fedora 38 update for mingw-python-werkzeug
- SUSE update for python-Werkzeug
- SUSE update for python-Werkzeug
- Ubuntu update for python-werkzeug
- SUSE update for python-Werkzeug
- SUSE update for python-Werkzeug
- Code injection in IBM Process Mining
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in IBM Security QRadar EDR
- Code Injection in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Code injection in IBM Watson Discovery for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Suite software
- Code Injection in Red Hat OpenShift Container Platform 4.15 packages
- Code injection in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM QRadar SIEM
- Code Injection in Red Hat OpenStack 17.1
- Code Injection in Red Hat OpenStack 17.1
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Multiple vulnerabilities in IBM Concert Software
- Code Injection in Red Hat OpenStack 16.2 packages
- Multiple vulnerabilities in IBM Watson Machine Learning Accelerator on Cloud Pak for Data
- Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component
- IBM watsonx Assistant Cartridge and IBM watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component update for Werkzeug
- Multiple vulnerabilities in QRadar Advisor With Watson for IBM QRadar SIEM
- Anolis OS update for python-werkzeug
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- IBM Cloud Pak for Data update for Werkzeug
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- IBM Storage Ceph update for Werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP4 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 22.03 LTS SP3 update for python-werkzeug
- openEuler 20.03 LTS SP4 update for python-werkzeug
- Multiple vulnerabilities in IBM watsonx.data