Pallets Werkzeug before 0.15.5 is susceptible to local file inclusion because SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
id: CVE-2019-14322
info:
name: Pallets Werkzeug <0.15.5 - Local File Inclusion
author: madrobot
...