Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-46136
HistoryOct 25, 2023 - 12:00 a.m.

CVE-2023-46136

2023-10-2500:00:00
ubuntu.com
ubuntu.com
18
werkzeug
wsgi
vulnerability
patched
3.0.1
denial of service
multipart data
endpoint
cpu time
worker processes
unix

8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

21.4%

Werkzeug is a comprehensive WSGI web application library. If an upload of a
file that starts with CR or LF and then is followed by megabytes of data
without these characters: all of these bytes are appended chunk by chunk
into internal bytearray and lookup for boundary is performed on growing
buffer. This allows an attacker to cause a denial of service by sending
crafted multipart data to an endpoint that will parse it. The amount of CPU
time required can block worker processes from handling legitimate requests.
This vulnerability has been patched in version 3.0.1.

8 High

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

21.4%