Directory Traversal The advisory has been revoked - it doesn't affect any version of package python3-werkzeug  (opens in a new tab)


Threat Intelligence

EPSS
1.68% (74th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL8-PYTHON3WERKZEUG-6140710
  • published30 Dec 2023
  • disclosed15 Feb 2023

Introduced: 15 Feb 2023

CVE-2022-41722  (opens in a new tab)
CWE-22  (opens in a new tab)

Amendment

The Red Hat security team deemed this advisory irrelevant for RHEL:8.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3-werkzeug package and not the python3-werkzeug package as distributed by RHEL.

A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path ".\c:\b".