CVE-2014-3137

Description

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.94

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-3137 are fixed in Python-bottle 0.10.12Windows
Vulnerabilities CVE-2014-3137 are fixed in Python-bottle 0.11.7Windows
Vulnerabilities CVE-2014-3137 are fixed in Python-bottle 0.12.6Windows
python-bottle security update(DSA-2948-1) python-bottle_0.12.9-1_all.debLinux
python-bottle security update(DSA-2948-1) python-bottle_0.12.9-1_all.debLinux
python-bottle security update(DSA-2948-1) python-bottle_0.10.11-1+deb7u1_all.debLinux
python-bottle regression update(DSA-3743-2) python-bottle_0.12.9-1_all.debLinux
Vulnerabilities CVE-2014-3137 are fixed in Python-bottle for linux 0.10.12Linux
Vulnerabilities CVE-2014-3137 are fixed in Python-bottle for linux 0.11.7Linux
Vulnerabilities CVE-2014-3137 are fixed in Python-bottle for linux 0.12.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234