SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3137

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a…

MEDIUM 6.8EPSS 3.13%

Does this matter?

Lower severity and a low EPSS score (3.13%). Track it; it rarely justifies an emergency change on its own.

Description

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
3.13% probability · 87th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
bottlepy/bottle
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.