Junglewise Threat Intelligence

CVE-2016-9964: PYSEC-2016-24 - redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233

CVE-2016-9964 · Severity: low · CVSS 3 · Published 2016-12-16

Technologies: bottle (PyPI). Vendors: PyPI.

Executive brief

redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.

Affected products

  • PyPI bottle

Related threats