CVE-2023-23934
Description
Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like =value instead of key=value. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like =__Host-test=bad for another subdomain. Werkzeug prior to 2.2.3 will parse the cookie =__Host-test=bad as __Host-test=bad`. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key. The issue is fixed in Werkzeug 2.2.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
WerkzeugPyPI | < 2.2.3 | 2.2.3 |
Affected products
4- osv-coords3 versionspkg:apk/chainguard/kubeflow-pipelines-visualization-serverpkg:apk/wolfi/kubeflow-pipelines-visualization-serverpkg:pypi/werkzeug
< 2.4.0-r0+ 2 more
- (no CPE)range: < 2.4.0-r0
- (no CPE)range: < 2.4.0-r0
- (no CPE)range: < 2.2.3
Patches
Vulnerability mechanics
References
9- github.com/pallets/werkzeug/commit/cf275f42acad1b5950c50ffe8ef58fe62cdce028nvdPatchWEB
- github.com/advisories/GHSA-px8h-6qxv-m22qghsaADVISORY
- github.com/pallets/werkzeug/security/advisories/GHSA-px8h-6qxv-m22qnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-23934ghsaADVISORY
- github.com/pallets/werkzeug/releases/tag/2.2.3nvdRelease NotesWEB
- github.com/pypa/advisory-database/tree/main/vulns/werkzeug/PYSEC-2023-57.yamlghsaWEB
- security.netapp.com/advisory/ntap-20230818-0003ghsaWEB
- www.debian.org/security/2023/dsa-5470nvdWEB
- security.netapp.com/advisory/ntap-20230818-0003/nvd
News mentions
0No linked articles in our index yet.