CVE-2024-34069 is a cross-site request forgery vulnerability in the Werkzeug debugger. An attacker can use an attacker-controlled domain and subdomain to induce a developer to enter the debugger PIN, then access a debugger instance that is bound only to localhost. The attacker must also identify an application URL that causes the debugger to be invoked. Werkzeug corrected the issue in version 3.0.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module: 'werkzeug_debug_rce.rb', which exploits a remote code execution vulnerability in the Werkzeug debugger console (CVE-2024-34069). The exploit targets web applications (such as Flask or Django) that have the Werkzeug debugger enabled and exposed to the network. The module supports multiple authentication modes, including known or generated cookies and PINs, and can exploit a range of Werkzeug versions (0.10 through 3.0.3) on Linux, Windows, and macOS. The main attack vector is network-based, targeting the HTTP endpoint (default '/console') where the debugger is accessible. If successful, the exploit allows the attacker to execute arbitrary Python code on the target server. The code is written in Ruby and is designed to be used within the Metasploit framework. The repository is well-structured, with clear targeting information, payload delivery, and support for various authentication scenarios.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
Unknown
A Python Werkzeug vulnerability that may allow a user to execute code on a developer's machine. Red Hat addressed it in the OpenShift Container Platform 4.12.64 security update.
A Python Werkzeug vulnerability that could permit a user to execute code on a developer's machine, addressed through the updated Red Hat Ceph Storage 7.1 container image.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.