Bugzilla – Bug 1145383
VUL-0: CVE-2019-14806: python-Werkzeug: when used with Docker, has insufficient debugger PIN randomness
Last modified: 2022-11-15 11:21:20 UTC
CVE-2019-14806 Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-14806 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-14806.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14806 https://github.com/pallets/werkzeug/commit/00bc43b1672e662e5e3b8cecd79e67fc968fa246 https://palletsprojects.com/blog/werkzeug-0-15-3-released/ https://github.com/pallets/werkzeug/blob/7fef41b120327d3912fbe12fb64f1951496fcf3e/src/werkzeug/debug/__init__.py#L168
tracking all codestreams as affected: - SUSE:SLE-12:Update - SUSE:SLE-12-SP3:Update:Products:Cloud8:Update - SUSE:SLE-12-SP4:Update:Products:Cloud9:Update - SUSE:SLE-15:Update - SUSE:SLE-15-SP1:Update
This is an autogenerated message for OBS integration: This bug (1145383) was mentioned in https://build.opensuse.org/request/show/723279 Factory / python-Werkzeug
SR's are: - SLE-15-SP1: https://build.suse.de/request/show/198840 - SLE-15: https://build.suse.de/request/show/198842 - SUSE:SLE-12-SP4:Update:Products:Cloud9:Update: https://build.suse.de/request/show/198844 - SUSE:SLE-12-SP3:Update:Products:Cloud8:Update: https://build.suse.de/request/show/198847 Not sure if SUSE:SLE-12:Update is really affected. It's not using the machine-id to generate the PIN. But this seems to be only affecting debug mode and upstream (see https://werkzeug.palletsprojects.com/en/0.15.x/debug/ ) discourages the debugger usage in production.
SUSE-SU-2019:2308-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1145383 CVE References: CVE-2019-14806 Sources used: SUSE Linux Enterprise Module for Packagehub Subpackages 15 (src): python-Werkzeug-0.12.2-3.3.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): python-Werkzeug-0.12.2-3.3.1, python-Werkzeug-doc-0.12.2-3.3.1 SUSE Linux Enterprise Module for Basesystem 15 (src): python-Werkzeug-0.12.2-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:2118-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1145383 CVE References: CVE-2019-14806 Sources used: openSUSE Leap 15.0 (src): python-Werkzeug-0.12.2-lp150.2.3.1, python-Werkzeug-doc-0.12.2-lp150.2.3.1
SUSE-SU-2019:2358-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1145383 CVE References: CVE-2019-14806 Sources used: SUSE OpenStack Cloud Crowbar 8 (src): python-Werkzeug-0.12.2-3.3.1 SUSE OpenStack Cloud 8 (src): python-Werkzeug-0.12.2-3.3.1 HPE Helion Openstack 8 (src): python-Werkzeug-0.12.2-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:2365-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1145383 CVE References: CVE-2019-14806 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): python-Werkzeug-0.14.1-6.3.1, python-Werkzeug-doc-0.14.1-6.3.1 SUSE Linux Enterprise Module for Basesystem 15-SP1 (src): python-Werkzeug-0.14.1-6.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:2145-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1145383 CVE References: CVE-2019-14806 Sources used: openSUSE Leap 15.1 (src): python-Werkzeug-0.14.1-lp151.2.3.1, python-Werkzeug-doc-0.14.1-lp151.2.3.1
SUSE-SU-2019:2400-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1145383 CVE References: CVE-2019-14806 Sources used: SUSE OpenStack Cloud Crowbar 9 (src): python-Werkzeug-0.14.1-3.3.1 SUSE OpenStack Cloud 9 (src): python-Werkzeug-0.14.1-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:2365-2: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1145383 CVE References: CVE-2019-14806 Sources used: SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1 (src): python-Werkzeug-0.14.1-6.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
cloud-bugs, cloud you please handle the submission for SUSE:SLE-12-SP1:Update? :)
SUSE-SU-2022:3977-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1145383 CVE References: CVE-2019-14806 JIRA References: Sources used: SUSE Linux Enterprise Module for Public Cloud 12 (src): python-Werkzeug-0.12.2-10.10.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.