CVE-2019-14806: High severity werkzeug vulnerability
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-14806?
CVE-2019-14806 is a vulnerability found in Pallets Werkzeug before 0.15.3 when used with Docker, which has insufficient debugger PIN randomness.
How does CVE-2019-14806 affect the software?
CVE-2019-14806 affects Pallets Werkzeug before 0.15.3 when used with Docker.
What is the severity of CVE-2019-14806?
The severity of CVE-2019-14806 is high with a CVSSv3 score of 7.5.
How can I fix CVE-2019-14806?
To fix CVE-2019-14806, upgrade to version 0.15.3 of Pallets Werkzeug or a higher version.
Where can I find more information about CVE-2019-14806?
You can find more information about CVE-2019-14806 at the following references: [1](https://nvd.nist.gov/vuln/detail/CVE-2019-14806), [2](https://github.com/pallets/werkzeug/blob/7fef41b120327d3912fbe12fb64f1951496fcf3e/src/werkzeug/debug/__init__.py#L168), [3](https://github.com/pallets/werkzeug/commit/00bc43b1672e662e5e3b8cecd79e67fc968fa246)