—
PYSEC-2019-140
Quick fix
PYSEC-2019-140 — werkzeug: upgrade to the fixed version with the command below.
pip install --upgrade 'werkzeug>=00bc43b1672e662e5e3b8cecd79e67fc968fa246'Details
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/werkzeug
Introduced in:
0Fixed in: 00bc43b1672e662e5e3b8cecd79e67fc968fa246Fix
pip install --upgrade 'werkzeug>=00bc43b1672e662e5e3b8cecd79e67fc968fa246'References
- https://github.com/pallets/werkzeug/commit/00bc43b1672e662e5e3b8cecd79e67fc968fa246[FIX]
- https://github.com/pallets/werkzeug/blob/7fef41b120327d3912fbe12fb64f1951496fcf3e/src/werkzeug/debug/__init__.py#L168[WEB]
- https://palletsprojects.com/blog/werkzeug-0-15-3-released/[ARTICLE]
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00034.html[WEB]
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00047.html[WEB]
- https://github.com/advisories/GHSA-gq9m-qvpx-68hc[ADVISORY]