漏洞描述
Pallets Werkzeug before 0.15.5 is susceptible to local file inclusion because SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
palletsprojects.comhttps://palletsprojects.com/blog/werkzeug-0-15-5-released/↗packetstormsecurity.comhttp://packetstormsecurity.com/files/163398/Pallets-Werkzeug-0.15.4-Path-Traversal.html↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2019-14322↗github.comhttps://github.com/faisalfs10x/CVE-2019-14322-scanner↗