Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-3137

Опубликовано: 25 окт. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8

Описание

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

РелизСтатусПримечание
artful

not-affected

0.12.6-1
bionic

not-affected

0.12.6-1
cosmic

not-affected

0.12.6-1
devel

not-affected

0.12.6-1
disco

not-affected

0.12.6-1
eoan

not-affected

0.12.6-1
esm-apps/bionic

not-affected

0.12.6-1
esm-apps/focal

not-affected

0.12.6-1
esm-apps/jammy

not-affected

0.12.6-1
esm-apps/xenial

not-affected

0.12.6-1

Показывать по

Ссылки на источники

6.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

debian
больше 11 лет назад

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before ...

CVSS3: 9.8
github
больше 3 лет назад

Bottle does not properly limit content-types

6.8 Medium

CVSS2