Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Question regarding CVE-2022-29361 #2420

Closed
acipm opened this issue May 25, 2022 · 3 comments
Closed

Question regarding CVE-2022-29361 #2420

acipm opened this issue May 25, 2022 · 3 comments

Comments

@acipm
Copy link

acipm commented May 25, 2022

I have a question regarding the HTTP request smuggling vulnerability CVE-2022-29361 in werkzeug.

The resources provided at mitre seem not to be pointing to a fix. I tried to find a fix but was unsuccessful.

Would it be possible for you to link to a fixing commit or provide a security advisory here? Thanks a lot!

@davidism
Copy link
Member

This cve is invalid, if you're running the dev server in production you have bigger security issues. The dev server is never intended to be run in production. The cve is also misattributed, it is about Python's http.server.

That said, upgrade Werkzeug

@acipm
Copy link
Author

acipm commented May 25, 2022

Thank you for your reply. If this is invalid could you please dispute the CVE at mitre?
You can do that here. Just link this issue, it should be sufficient.

@davidism
Copy link
Member

From past experience, disputing is not worth my time. I don't put much faith in the CVE system now, as it is too easy for anyone to open issues without being involved or understanding them, and the dispute process went nowhere last time I tried.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Jun 9, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants