Wrkzeug's incorrect parsing of nameless cookies leads to __Host- cookies bypass
Published Feb 14, 2023
3.5
LOWCVSS 3.1
EPSS 0.51%
Description
Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised application on an adjacent subdomain to exploit this to set a cookie like `=__Host-test=bad` for another subdomain. Werkzeug prior to 2.2.3 will parse the cookie `=__Host-test=bad` as __Host-test=bad`. If a Werkzeug application is running next to a vulnerable or malicious subdomain which sets such a cookie using a vulnerable browser, the Werkzeug application will see the bad cookie value but the valid cookie key. The issue is fixed in Werkzeug 2.2.3.
Affected products
-
- Version < 2.2.3StatusaffectedConstraints-
- Version
- < 2.2.3
No data.
Red Hat Ceph Storage 7.1
oath-toolkit-0:2.6.12-1.el8cp
Fixed · RHSA-2025:4664
Red Hat Ceph Storage 8.1
oath-toolkit-0:2.6.12-1.el9cp
Fixed · RHSA-2025:9775
Red Hat OpenStack Platform 17.0
python-werkzeug-0:2.0.1-5.el9ost
Fixed · RHSA-2023:1018
Red Hat Enterprise Linux 7
python-werkzeug
Out of support scope
Red Hat Enterprise Linux 8
python-werkzeug
Fix deferred
Red Hat OpenShift Container Platform 4
python-werkzeug
Affected
Red Hat OpenStack Platform 16.1
python-werkzeug
Fix deferred
Red Hat OpenStack Platform 16.2
openstack-designate
Fix deferred
Red Hat OpenStack Platform 16.2
python-werkzeug
Fix deferred
Red Hat Quay 3
quay/quay-rhel8
Fix deferred
Red Hat Storage 3
python-werkzeug
Out of support scope
Red Hat Update Infrastructure 3 for Cloud Providers
python-werkzeug
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 7.1 | oath-toolkit-0:2.6.12-1.el8cp | Fixed | RHSA-2025:4664 |
| Red Hat Ceph Storage 8.1 | oath-toolkit-0:2.6.12-1.el9cp | Fixed | RHSA-2025:9775 |
| Red Hat OpenStack Platform 17.0 | python-werkzeug-0:2.0.1-5.el9ost | Fixed | RHSA-2023:1018 |
| Red Hat Enterprise Linux 7 | python-werkzeug | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | python-werkzeug | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | python-werkzeug | Affected | n/a |
| Red Hat OpenStack Platform 16.1 | python-werkzeug | Fix deferred | n/a |
| Red Hat OpenStack Platform 16.2 | openstack-designate | Fix deferred | n/a |
| Red Hat OpenStack Platform 16.2 | python-werkzeug | Fix deferred | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Fix deferred | n/a |
| Red Hat Storage 3 | python-werkzeug | Out of support scope | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | python-werkzeug | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2023-23934 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2170243 Issue Tracking
- https://github.com/advisories/GHSA-px8h-6qxv-m22q Advisory
- https://github.com/pallets/werkzeug/commit/cf275f42acad1b5950c50ffe8ef58fe62cdce028 x_refsource_MISCPatch
- https://github.com/pallets/werkzeug/releases/tag/2.2.3 x_refsource_MISCRelease Notes
- https://github.com/pallets/werkzeug/security/advisories/GHSA-px8h-6qxv-m22q x_refsource_CONFIRMVendor Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/werkzeug/PYSEC-2023-57.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2023-23934
- https://security.netapp.com/advisory/ntap-20230818-0003
- https://www.cve.org/CVERecord?id=CVE-2023-23934
- https://www.debian.org/security/2023/dsa-5470
Change history (0)
No recorded changes yet.