CVE-2014-3137
published 2014-10-25CVE-2014-3137: Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass…
PriorityP341medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.10%
86.3th percentile
Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
| bottlepy | bottle | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Bottle does not properly limit content-types
ghsa·2022-05-17
CVE-2014-3137 [HIGH] CWE-20 Bottle does not properly limit content-types
Bottle does not properly limit content-types
Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a `;` (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.
OSV
Bottle does not properly limit content-types
osv·2022-05-17
CVE-2014-3137 [HIGH] Bottle does not properly limit content-types
Bottle does not properly limit content-types
Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a `;` (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.
OSV
CVE-2014-3137: Bottle 0
osv·2014-10-25·CVSS 6.8
CVE-2014-3137 [MEDIUM] CVE-2014-3137: Bottle 0
Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.
Debian
CVE-2014-3137: python-bottle - Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 doe...
vendor_debian·2014·CVSS 6.8
CVE-2014-3137 [MEDIUM] CVE-2014-3137: python-bottle - Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 doe...
Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 0.12.6-1)
bullseye: resolved (fixed in 0.12.6-1)
forky: resolved (fixed in 0.12.6-1)
sid: resolved (fixed in 0.12.6-1)
trixie: resolved (fixed in 0.12.6-1)
No detection rules found.
No public exploits indexed.
http://www.debian.org/security/2014/dsa-2948http://www.openwall.com/lists/oss-security/2014/05/01/15https://bugzilla.redhat.com/show_bug.cgi?id=1093255https://github.com/defnull/bottle/issues/616http://www.debian.org/security/2014/dsa-2948http://www.openwall.com/lists/oss-security/2014/05/01/15https://bugzilla.redhat.com/show_bug.cgi?id=1093255https://github.com/defnull/bottle/issues/616
2014-10-25
Published