CVE-2024-49766

Updated on 25 Oct 2024

Severity

6.3 Medium severity

Details

CVSS score
6.3
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Overview

About vulnerability

On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug’s safe_join() relies on this check, and so can produce a path that is not safe, potentially allowing unintended access to data. Applications using Python >= 3.11, or not using Windows, are not vulnerable.

Details

Affected product:
Flask , Werkzeug
Affected packages:
werkzeug (+11 more)

Fixes