UBUNTU-CVE-2016-10516
Dashboard / Vulnerabilities / UBUNTU-CVE-2016-10516
UBUNTU-CVE-2016-10516
Summary:
Details: Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
References: https://ubuntu.com/security/CVE-2016-10516, http://blog.neargle.com/2016/09/21/flask-src-review-get-a-xss-from-debuger/, https://github.com/pallets/werkzeug/pull/1001, https://ubuntu.com/security/notices/USN-3463-1, https://www.cve.org/CVERecord?id=CVE-2016-10516
Affected packages
Package
Name: python-werkzeug
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1.1ubuntu2.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
