Executive brief
redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.
Affected products
- PyPI bottle
Junglewise Threat Intelligence
CVE-2016-9964 · Severity: low · CVSS 3 · Published 2016-12-16
Technologies: bottle (PyPI). Vendors: PyPI.
redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.