Записи bottlepy
4 опубликованных записей вендора bottlepy.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation1
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')1
- CWE-755 Improper Handling of Exceptional Conditions1
- CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-31799Эксплойта нет | Bottle before 0.12.20 mishandles errors during early request binding.bottlepy · bottle · CWE-755 | Критическая9,8 | — | 2,1 % | 2 июн. 2022 г. |
28Наблюдать | CVE-2014-3137Эксплойта нет | Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attabottlepy · bottle · CWE-20 | Средняя6,8 | — | 3,1 % | 25 окт. 2014 г. |
28Наблюдать | CVE-2020-28473Эксплойта нет | The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking.bottlepy · bottle · CWE-444 | Средняя6,8 | — | 1,8 % | 18 янв. 2021 г. |
27Наблюдать | CVE-2016-9964Эксплойта нет | redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233bottlepy · bottle · CWE-93 | Средняя6,5 | — | 1,8 % | 16 дек. 2016 г. |
- CVE-2022-3179940В плане
Bottle before 0.12.20 mishandles errors during early request binding.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bottlepy · bottle2 июн. 2022 г.
- CVE-2014-313728Наблюдать
Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote atta
СредняяCVSS 6,8Эксплойта нетEPSS 3 %bottlepy · bottle25 окт. 2014 г.
- CVE-2020-2847328Наблюдать
The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking.
СредняяCVSS 6,8Эксплойта нетEPSS 2 %bottlepy · bottle18 янв. 2021 г.
- CVE-2016-996427Наблюдать
redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233
СредняяCVSS 6,5Эксплойта нетEPSS 2 %bottlepy · bottle16 дек. 2016 г.