Path traversal in Werkzeug - CVE-2024-49766

 

Path traversal in Werkzeug - CVE-2024-49766

Published: October 31, 2024


Vulnerability identifier: #VU99566
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-49766
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to input validation error when processing UNC paths on Windows. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.


Affected software

Werkzeug
watsonx.data
IBM Concert Software
IBM Cloud Pak for Data System
IBM Cloud Pak for Security
IBM Process Mining
IBM Watson Knowledge Catalog in Cloud Pak for Data
Splunk User Behavior Analytics (UBA)
IBM Spectrum Protect Plus
Oracle Communications Cloud Native Core DBTier
Qradar Advisor
IBM Fusion HCI
IBM Maximo Application Suite
QRadar Suite
watsonx Code Assistant for Ansible
Storage Ceph
Security QRadar EDR
IBM Cloud Pak for Watson AIOps
Maximo Application Suite - IoT Component
Anolis OS
python3-werkzeug-doc
python3-werkzeug

How to mitigate CVE-2024-49766

Install update from vendor's website.

Werkzeug - update to 3.0.6
IBM Concert Software - update to 1.0.5
IBM Cloud Pak for Data System - update to 1.0.10.0
IBM Cloud Pak for Security - update to 1.11.3.0
QRadar Suite - update to 1.11.3.0
IBM Process Mining - update to 2.0
watsonx.data - update to 2.3.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
watsonx Code Assistant for Ansible - update to 5.1.1
Splunk User Behavior Analytics (UBA) - update to 5.4.3
Storage Ceph - update to 8.1
IBM Spectrum Protect Plus - update to 10.1.17.1
Qradar Advisor - update to 2.6.6
IBM Fusion HCI - update to 2.9.0
python3-werkzeug-doc - update to 3.0.1-4
python3-werkzeug - update to 3.0.1-4
Security QRadar EDR - update to 3.12.14
IBM Cloud Pak for Watson AIOps - update to 4.8.0
Maximo Application Suite - IoT Component - addressed in versions 8.7.19, 8.8.15, 9.0.5
IBM Maximo Application Suite - addressed in versions 8.10.21, 8.11.18, 9.0.7

External References

Related Security Bulletins