Vulnerabilities
Vulnerable Software
Palletsprojects:  Security Vulnerabilities
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
CVSS Score
7.5
EPSS Score
0.901
Published
2019-07-28
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.
CVSS Score
7.5
EPSS Score
0.003
Published
2019-07-17
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
CVSS Score
8.6
EPSS Score
0.01
Published
2019-04-08
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
CVSS Score
8.6
EPSS Score
0.027
Published
2019-04-07
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability appears to have been fixed in 0.12.3. NOTE: this may overlap CVE-2019-1010083.
CVSS Score
7.5
EPSS Score
0.006
Published
2018-08-20
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-10-23


Contact Us

Shodan ® - All rights reserved