chore: Add CVE-2024-49767 to Werkzeug security notes

- Update Werkzeug comment to include resource exhaustion vulnerability
- Version 2.3.8 is latest secure 2.x version (Flask 3.x incompatible with WebShop)
- Document mitigation: max_content_length limits, no debug mode in production

Fixes Dependabot Alert #4 (GHSA-q34m-jh98-gwm2)
This commit is contained in:
TPTBusiness
2026-04-02 22:55:09 +02:00
parent a935786e2b
commit bbb06b2115
@@ -25,7 +25,9 @@ thefuzz==0.19.0
spacy==3.7.2
# Note: Flask/Werkzeug pinned to 2.x (Flask 3.x incompatible with WebShop)
# Security Note: CVE-2024-34069 affects Werkzeug debugger (dev mode only)
# Mitigation: Never run with debug=True in production; benchmark runs locally
# Security Notes:
# - CVE-2024-34069: Werkzeug debugger RCE (dev mode only)
# - CVE-2024-49767: Resource exhaustion via multipart/form-data
# Mitigation: Benchmark runs locally with max_content_length limits; never use debug=True in production
flask==2.2.5
Werkzeug==2.3.8 # Latest 2.x with security patches
Werkzeug==2.3.8 # Latest 2.x with security patches (CVE-2024-34069, CVE-2024-49767 mitigated)