• CVE-2024-34069

发布时间: 2025年8月15日

修改时间: 2025年8月22日

概要

Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's machine under some circumstances. This requires the attacker to get the developer to interact with a domain and subdomain they control, and enter the debugger PIN, but if they are successful it allows access to the debugger even if it is only running on localhost. This also requires the attacker to guess a URL in the developer's application that will trigger the debugger. This vulnerability is fixed in 3.0.3.

CVSS v3 指标

NVD openEuler
Confidentiality High
Attack Vector Network
CVSS评分 N/A 7.5
Attack Complexity High
Privileges Required None
Scope Unchanged
Integrity High
User Interaction Required
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2810 python-werkzeug security update 2025年9月8日

影响产品

产品 状态
KY3.4-5 python-werkzeug Fixed
KY3.5.3 python-werkzeug Fixed
KY3.5.2 python-werkzeug Fixed