Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-23934
HistoryFeb 14, 2023 - 12:00 a.m.

CVE-2023-23934

2023-02-1400:00:00
ubuntu.com
ubuntu.com
10
werkzeug library
wsgi web application
nameless cookies
vulnerable browser
subdomain
cookie exploitation
security issue
fix

3.5 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

21.7%

Werkzeug is a comprehensive WSGI web application library. Browsers may
allow “nameless” cookies that look like =value instead of key=value. A
vulnerable browser may allow a compromised application on an adjacent
subdomain to exploit this to set a cookie like =__Host-test=bad for
another subdomain. Werkzeug prior to 2.2.3 will parse the cookie
=__Host-test=bad as __Host-test=bad`. If a Werkzeug application is
running next to a vulnerable or malicious subdomain which sets such a
cookie using a vulnerable browser, the Werkzeug application will see the
bad cookie value but the valid cookie key. The issue is fixed in Werkzeug
2.2.3.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchpython-werkzeug< 0.14.1+dfsg1-1ubuntu0.2UNKNOWN
ubuntu20.04noarchpython-werkzeug< 0.16.1+dfsg1-2ubuntu0.1UNKNOWN
ubuntu22.04noarchpython-werkzeug< 2.0.2+dfsg1-1ubuntu0.22.04.1UNKNOWN
ubuntu22.10noarchpython-werkzeug< 2.0.2+dfsg1-3ubuntu0.22.10.1UNKNOWN
ubuntu23.04noarchpython-werkzeug< 2.2.2-2ubuntu0.1UNKNOWN
ubuntu16.04noarchpython-werkzeug< 0.10.4+dfsg1-1ubuntu1.2+esm1UNKNOWN

3.5 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

0.001 Low

EPSS

Percentile

21.7%