CVE-2022-31799
published 2022-06-02CVE-2022-31799: Bottle before 0.12.20 mishandles errors during early request binding.
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.87%
77.0th percentile
Bottle before 0.12.20 mishandles errors during early request binding.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bottlepy | bottle | < 0.12.20 | 0.12.20 |
| bottlepy | bottle | >= 0 < 0.12.20 | 0.12.20 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | python-bottle | < python-bottle 0.12.20-1 (bookworm) | python-bottle 0.12.20-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Bottle vulnerability
vendor_ubuntu·2022-07-26·CVSS 9.8
CVE-2022-31799 [CRITICAL] Bottle vulnerability
Title: Bottle vulnerability
Summary: Bottle could be made to leak sensitive information if it received a specially
crafted request
USN-5532-1 fixed a vulnerability in Bottle. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM
Original advisory details:
It was discovered that Bottle incorrectly handled errors during early request
binding. An attacker could possibly use this issue to disclose sensitive
information. (CVE-2022-31799)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Bottle vulnerability
vendor_ubuntu·2022-07-26·CVSS 9.8
CVE-2022-31799 [CRITICAL] Bottle vulnerability
Title: Bottle vulnerability
Summary: Bottle could be made to leak sensitive information if it received a specially
crafted request.
It was discovered that Bottle incorrectly handled errors during early request
binding. An attacker could possibly use this issue to disclose sensitive
information. (CVE-2022-31799)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-31799: python-bottle - Bottle before 0.12.20 mishandles errors during early request binding.
vendor_debian·2022·CVSS 9.8
CVE-2022-31799 [CRITICAL] CVE-2022-31799: python-bottle - Bottle before 0.12.20 mishandles errors during early request binding.
Bottle before 0.12.20 mishandles errors during early request binding.
Scope: local
bookworm: resolved (fixed in 0.12.20-1)
bullseye: resolved (fixed in 0.12.19-1+deb11u1)
forky: resolved (fixed in 0.12.20-1)
sid: resolved (fixed in 0.12.20-1)
trixie: resolved (fixed in 0.12.20-1)
OSV
python-bottle vulnerability
osv·2022-07-26·CVSS 9.8
CVE-2022-31799 [CRITICAL] python-bottle vulnerability
python-bottle vulnerability
USN-5532-1 fixed a vulnerability in Bottle. This update provides the
corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM
Original advisory details:
It was discovered that Bottle incorrectly handled errors during early request
binding. An attacker could possibly use this issue to disclose sensitive
information. (CVE-2022-31799)
OSV
python-bottle vulnerability
osv·2022-07-26·CVSS 9.8
CVE-2022-31799 [CRITICAL] python-bottle vulnerability
python-bottle vulnerability
It was discovered that Bottle incorrectly handled errors during early request
binding. An attacker could possibly use this issue to disclose sensitive
information. (CVE-2022-31799)
OSV
Denial of service in bottle
osv·2022-06-03
CVE-2022-31799 [CRITICAL] Denial of service in bottle
Denial of service in bottle
Bottle before 0.12.20 mishandles errors during early request binding.
GHSA
Denial of service in bottle
ghsa·2022-06-03
CVE-2022-31799 [CRITICAL] CWE-755 Denial of service in bottle
Denial of service in bottle
Bottle before 0.12.20 mishandles errors during early request binding.
OSV
CVE-2022-31799: Bottle before 0
osv·2022-06-02·CVSS 9.8
CVE-2022-31799 [CRITICAL] CVE-2022-31799: Bottle before 0
Bottle before 0.12.20 mishandles errors during early request binding.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/bottlepy/bottle/commit/a2b0ee6bb4ce88895429ec4aca856616244c4c4chttps://github.com/bottlepy/bottle/commit/e140e1b54da721a660f2eb9d58a106b7b3ff2f00https://github.com/bottlepy/bottle/compare/0.12.19...0.12.20https://lists.debian.org/debian-lts-announce/2022/06/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE7U6J45PUEXIYYVWJKPM6QXIRKDK4HD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KTLOQGMDZEPIYTFC2G53OQV2ULCGYS3F/https://www.debian.org/security/2022/dsa-5159https://github.com/bottlepy/bottle/commit/a2b0ee6bb4ce88895429ec4aca856616244c4c4chttps://github.com/bottlepy/bottle/commit/e140e1b54da721a660f2eb9d58a106b7b3ff2f00https://github.com/bottlepy/bottle/compare/0.12.19...0.12.20https://lists.debian.org/debian-lts-announce/2022/06/msg00010.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IE7U6J45PUEXIYYVWJKPM6QXIRKDK4HD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KTLOQGMDZEPIYTFC2G53OQV2ULCGYS3F/https://www.debian.org/security/2022/dsa-5159
2022-06-02
Published