Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Olivier Dony

#16725of 53,635
16.1Total CVSS
Vulnerabilities · 2
High
2
PT-2019-13607
7.5
2019-07-28
Pallets · Werkzeug · CVE-2019-14322
**Name of the Vulnerable Software and Affected Versions** Pallets Werkzeug versions prior to 0.15.5 **Description** The issue is related to how SharedDataMiddleware handles drive names, such as C:, in Windows pathnames. This mishandling can lead to potential security issues. **Recommendations** For versions prior to 0.15.5, update to version 0.15.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the SharedDataMiddleware to minimize the risk of exploitation.
PT-2019-7543
8.6
2019-04-08
Pallets · Jinja · CVE-2016-10745
**Name of the Vulnerable Software and Affected Versions** Pallets Jinja versions prior to 2.8.1 **Description** The issue allows a sandbox escape through the str.format function. **Recommendations** For versions prior to 2.8.1, update to version 2.8.1 or later to resolve the issue.