Junglewise Threat Intelligence

CVE-2014-3137: PYSEC-2014-77 - Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote atta

CVE-2014-3137 · Severity: low · CVSS 3.1 · Published 2014-10-25

Technologies: bottle (PyPI). Vendors: PyPI.

Executive brief

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

Affected products

  • PyPI bottle

Related threats