GHSA-g6x2-hccm-hh4m: Pip/Werkzeug vulnerability
Werkzeug's safejoin function allows Windows device names as filenames when they have an empty ADS marker on NTFS.
This was previously reported as https://github.com/pallets/werkzeug/security/advisories/GHSA-hgf8-39gv-g3f2, but the added filtering failed to account for the fact Windows allows special device names with an empty ADS marker, such as NUL:.
sendfromdirectory uses safejoin to safely serve files at user-specified paths under a directory. If the application is running on Windows and NTFS, and the requested path ends with a special device name, the file will be opened successfully, but reading will hang indefinitely.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/Werkzeugto a version that resolves this vulnerability.Fixed in 3.1.9
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
The issue applies when an application uses Werkzeug's send_from_directory on Windows with an NTFS filesystem and serves paths that users can specify. Other operating system and filesystem combinations are not identified as affected by the available information.
What does an attacker need to do to trigger the problem?
An attacker needs to request a path ending in a Windows special device name with an empty alternate data stream marker, such as NUL:. When send_from_directory passes that path through safe_join, opening the resulting path succeeds but reading it hangs indefinitely.
What is the likely impact of successful exploitation?
The affected file read hangs indefinitely. This can cause denial of service for requests or resources handling those reads.