CVE-2024-34069: high-severity vulnerability in pallets werkzeug
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
Published · Updated
Patch soon. It has a working public exploit.
Werkzeug's debugger can be exploited by attackers to run malicious code on a developer's computer if the developer visits an attacker-controlled website and enters the debugger PIN. This is dangerous because it gives attackers direct access to run commands on the developer's machine.
A CSRF protection bypass (CWE-352) combined with improper pathname handling in Werkzeug's debugger allows remote code execution. The attack requires social engineering to trick a developer into visiting an attacker-controlled domain, entering the debugger PIN, and guessing a URL that triggers the debugger; successful exploitation grants arbitrary code execution even when the debugger is bound to localhost.
In the same product, most dangerous first.