CVE-2023-22970
published 2023-05-26CVE-2023-22970: Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.47%
37.6th percentile
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| usebottles | bottles | < 51.0 | 51.0 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_oracle5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fvv8-mx97-fv82: Bottles before 51
ghsa_unreviewed·2023-05-26
CVE-2023-22970 [HIGH] GHSA-fvv8-mx97-fv82: Bottles before 51
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
Oracle
Oracle Oracle Communications Risk Matrix: Signaling (Spring Framework) — CVE-2022-22970
vendor_oracle·2023-01-15·CVSS 5.3
CVE-2022-22970 [MEDIUM] Oracle Oracle Communications Risk Matrix: Signaling (Spring Framework) — CVE-2022-22970
Oracle Oracle Communications Risk Matrix: Signaling (Spring Framework) vulnerability
CVE: CVE-2022-22970
CVSS: 5.3
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/bottlesdevs/Bottles/issues/2463https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N24KI3O3FWGKJSLATY35ZM3CHSABJ6WE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZJZEE4RAAK7OPVQNE4BOWUVQDVSZU6NJ/https://github.com/bottlesdevs/Bottles/issues/2463https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N24KI3O3FWGKJSLATY35ZM3CHSABJ6WE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZJZEE4RAAK7OPVQNE4BOWUVQDVSZU6NJ/
2023-05-26
Published