Skip to main content

Vendor/product archive

bottlepy / bottle CVEs

Beta · best-effort

4 CVEs tagged to bottlepy / bottle1 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2020-28473

Published Jan 18, 2021

The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters usi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9964

Published Dec 16, 2016

redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3137

Published Oct 25, 2014

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restric…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1