Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-3137

Опубликовано: 25 окт. 2014
Источник: debian
EPSS Низкий

Описание

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-bottlefixed0.12.6-1package
python-bottlenot-affectedsqueezepackage

EPSS

Процентиль: 76%
0.0094
Низкий

Связанные уязвимости

ubuntu
больше 11 лет назад

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

nvd
больше 11 лет назад

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

CVSS3: 9.8
github
больше 3 лет назад

Bottle does not properly limit content-types

EPSS

Процентиль: 76%
0.0094
Низкий