-
Notifications
You must be signed in to change notification settings - Fork 4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update dependency Werkzeug [SECURITY] #16
Closed
Closed
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Jan 14, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 14, 2024 20:17
72eadf6
to
8d18c47
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Jan 14, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 14, 2024 20:19
8d18c47
to
8dea9cb
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Jan 14, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 14, 2024 20:19
8dea9cb
to
6a18841
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Jan 14, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 14, 2024 20:29
6a18841
to
7c1d247
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Jan 14, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
2 times, most recently
from
January 15, 2024 07:16
99d940e
to
23f27c7
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Jan 15, 2024
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Jan 15, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 15, 2024 07:16
23f27c7
to
1b8636f
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Jan 15, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 15, 2024 07:17
1b8636f
to
73a230a
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Jan 15, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 15, 2024 07:18
73a230a
to
4dc793f
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Jan 15, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 15, 2024 07:20
4dc793f
to
26eea77
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Jan 15, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 15, 2024 07:20
26eea77
to
52deda2
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Jan 15, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 15, 2024 08:34
52deda2
to
2831366
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Jan 15, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 15, 2024 08:35
2831366
to
701daea
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Jan 15, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 15, 2024 08:36
701daea
to
d1dca38
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Jan 15, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
January 15, 2024 08:36
d1dca38
to
a1f2050
Compare
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 9, 2024 21:48
a25f22b
to
378bfe4
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Apr 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 9, 2024 21:48
378bfe4
to
e3dc406
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Apr 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 9, 2024 21:50
e3dc406
to
c762473
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Apr 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 9, 2024 21:50
c762473
to
8a9326b
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Apr 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 9, 2024 21:52
8a9326b
to
92aef15
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Apr 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 9, 2024 21:54
92aef15
to
ed6c3b5
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Apr 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
2 times, most recently
from
April 9, 2024 21:55
3d9839c
to
1671ca5
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Apr 9, 2024
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Apr 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
2 times, most recently
from
April 9, 2024 21:56
a558b90
to
75d5f8f
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Apr 9, 2024
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Apr 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 9, 2024 21:57
75d5f8f
to
606af0c
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Apr 9, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 9, 2024 21:57
606af0c
to
8a8fb45
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Apr 11, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 11, 2024 07:10
8a8fb45
to
0706233
Compare
renovate
bot
changed the title
Update dependency Werkzeug [SECURITY]
Update dependency Werkzeug to v2 [SECURITY]
Apr 11, 2024
renovate
bot
force-pushed
the
renovate/pypi-Werkzeug-vulnerability
branch
from
April 11, 2024 11:06
0706233
to
93df4a8
Compare
renovate
bot
changed the title
Update dependency Werkzeug to v2 [SECURITY]
Update dependency Werkzeug [SECURITY]
Apr 13, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==0.16.1
->==3.0.2
==0.16.1
->==2.2.3
GitHub Vulnerability Alerts
CVE-2023-23934
Browsers may allow "nameless" cookies that look like
=value
instead ofkey=value
. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like=__Host-test=bad
for another subdomain.Werkzeug <= 2.2.2 will parse the cookie
=__Host-test=bad
as__Host-test=bad
. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key.CVE-2023-25577
Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a small amount of bytes, but each requires CPU time to parse and may use more memory as Python data. If a request can be made to an endpoint that accesses
request.data
,request.form
,request.files
, orrequest.get_data(parse_form_data=False)
, it can cause unexpectedly high resource usage.This allows an attacker to cause a denial of service by sending crafted multipart data to an endpoint that will parse it. The amount of CPU time required can block worker processes from handling legitimate requests. The amount of RAM required can trigger an out of memory kill of the process. Unlimited file parts can use up memory and file handles. If many concurrent requests are sent continuously, this can exhaust or kill all available workers.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate. View repository job log here.