Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-873q-wpqr-xfgw

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.1
CVSS3: 9.8

Описание

Bottle does not properly limit content-types

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

Пакеты

Наименование

bottle

pip
Затронутые версииВерсия исправления

>= 0.10.0, < 0.10.12

0.10.12

Наименование

bottle

pip
Затронутые версииВерсия исправления

>= 0.11.0, < 0.11.7

0.11.7

Наименование

bottle

pip
Затронутые версииВерсия исправления

>= 0.12.0, < 0.12.6

0.12.6

EPSS

Процентиль: 76%
0.0094
Низкий

8.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 11 лет назад

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

nvd
больше 11 лет назад

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

debian
больше 11 лет назад

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before ...

EPSS

Процентиль: 76%
0.0094
Низкий

8.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20