USN-7093-1: Werkzeug vulnerability
It was discovered that Werkzeug incorrectly handled multiple form submission requests. A remote attacker could possibly use this issue to cause Werkzeug to consume resources, leading to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7093-1?
USN-7093-1 has a denial of service impact, which can affect system availability.
How do I fix USN-7093-1?
To fix USN-7093-1, update the python3-werkzeug package to at least version 3.0.3-1ubuntu0.1 or its equivalent for your Ubuntu release.
What versions of Ubuntu are affected by USN-7093-1?
USN-7093-1 affects Ubuntu versions 24.10, 24.04, and 22.04 that have vulnerable versions of the python3-werkzeug package.
Is there any workaround for USN-7093-1?
There is no specified workaround for USN-7093-1; updating the package is recommended.
What causes the vulnerability in USN-7093-1?
The vulnerability in USN-7093-1 is caused by Werkzeug's mishandling of multiple form submission requests, which can lead to resource exhaustion.