Skip to content
Noroxi

bottlepy records

4 published records for vendor bottlepy.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

4 records
  • Bottle before 0.12.20 mishandles errors during early request binding.

    CriticalCVSS 9.8No exploitEPSS 2%

    bottlepy · bottleJun 2, 2022

  • CVE-2014-3137
    28Monitor

    Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote atta

    MediumCVSS 6.8No exploitEPSS 3%

    bottlepy · bottleOct 25, 2014

  • The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking.

    MediumCVSS 6.8No exploitEPSS 2%

    bottlepy · bottleJan 18, 2021

  • CVE-2016-9964
    27Monitor

    redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233

    MediumCVSS 6.5No exploitEPSS 2%

    bottlepy · bottleDec 16, 2016