Skip to main content

Vendor archive

bottlepy CVEs

Beta · best-effort

4 CVEs tagged to vendor bottlepy1 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2020-28473

Published Jan 18, 2021

The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters usi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9964

Published Dec 16, 2016

redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3137

Published Oct 25, 2014

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restric…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1