{"id":"UBUNTU-CVE-2024-49766","details":"Werkzeug is a Web Server Gateway Interface web application library. On Python \u003c 3.11 on Windows, os.path.isabs() does not catch UNC paths like //server/share. Werkzeug's safe_join() relies on this check, and so can produce a path that is not safe, potentially allowing unintended access to data. Applications using Python \u003e= 3.11, or not using Windows, are not vulnerable. Werkzeug version 3.0.6 contains a patch.","modified":"2026-02-04T02:17:35.933015Z","published":"2024-10-28T00:00:00Z","withdrawn":"2025-06-23T15:59:18Z","related":["CVE-2024-49766"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-49766"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-49766"},{"type":"REPORT","url":"https://github.com/pallets/werkzeug/security/advisories/GHSA-f9vj-2wh5-fj8j"},{"type":"REPORT","url":"https://github.com/pallets/werkzeug/commit/87cc78a25f782f8c59fbde786840a00cf0d09b3d"},{"type":"REPORT","url":"https://github.com/pallets/werkzeug/commit/2767bcb10a7dd1c297d812cc5e6d11a474c1f092"},{"type":"REPORT","url":"https://github.com/pallets/werkzeug/releases/tag/3.0.6"}],"affected":[{"package":{"name":"python-werkzeug","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/python-werkzeug?arch=src?distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.10.4+dfsg1-1ubuntu1","0.10.4+dfsg1-1ubuntu1.1","0.10.4+dfsg1-1ubuntu1.2","0.10.4+dfsg1-1ubuntu1.2+esm1","0.10.4+dfsg1-1ubuntu1.2+esm2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-49766.json"}},{"package":{"name":"python-werkzeug","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/python-werkzeug?arch=src?distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.12.2+dfsg1-2","0.13+dfsg1-1","0.14.1+dfsg1-1","0.14.1+dfsg1-1ubuntu0.1","0.14.1+dfsg1-1ubuntu0.2","0.14.1+dfsg1-1ubuntu0.2+esm1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-49766.json"}},{"package":{"name":"python-werkzeug","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/python-werkzeug?arch=src?distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.14.1+dfsg1-4","0.15.6+dfsg1-1","0.16.0+dfsg1-1","0.16.1+dfsg1-1ubuntu1","0.16.1+dfsg1-2","0.16.1+dfsg1-2ubuntu0.1","0.16.1+dfsg1-2ubuntu0.2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-49766.json"}},{"package":{"name":"python-werkzeug","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/python-werkzeug?arch=src?distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.1+dfsg1-2","2.0.2+dfsg1-1","2.0.2+dfsg1-1ubuntu0.22.04.1","2.0.2+dfsg1-1ubuntu0.22.04.2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-49766.json"}},{"package":{"name":"python-werkzeug","ecosystem":"Ubuntu:24.10","purl":"pkg:deb/ubuntu/python-werkzeug?arch=src?distro=oracular"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.0.1-3","3.0.3-1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-49766.json"}},{"package":{"name":"python-werkzeug","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/python-werkzeug?arch=src?distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.2-3","3.0.1-1","3.0.1-2","3.0.1-3","3.0.1-3ubuntu0.1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-49766.json"}}],"schema_version":"1.7.3"}