Security features bypass in Bottle - CVE-2022-31799

 

Security features bypass in Bottle - CVE-2022-31799

Published: June 1, 2022


Vulnerability identifier: #VU63912
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31799
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to mishandling errors during early request binding. A remote attacker can exploit this vulnerability to launch further attacks on the system.


Affected software

Bottle
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Fedora
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Python for Scientific Computing
Splunk Universal Forwarder
Splunk Enterprise
python3-bottle (Ubuntu package)
python-bottle (Ubuntu package)
python2-bottle
python3-bottle
python-bottle
python-bottle-doc
python-bottle (Debian package)
IBM Cloud Pak for Data System
IBM Integrated Analytics System

How to mitigate CVE-2022-31799

Install updates from vendor's website.

Bottle - update to 0.12.20
Python for Scientific Computing - update to 4.2.1
Splunk Universal Forwarder - addressed in versions 9.0.7, 9.1.2
Splunk Enterprise - addressed in versions 9.0.7, 9.1.2
python3-bottle (Ubuntu package) - addressed in versions 0.12.13-1ubuntu0.2, 0.12.15-2.1ubuntu0.2, 0.12.19-1+deb11u1build0.22.04.1
python-bottle (Ubuntu package) - update to 0.12.13-1ubuntu0.2
python2-bottle - update to 0.12.13-9
python3-bottle - update to 0.12.13-9
python-bottle - update to 0.12.13-9
python-bottle-doc - update to 0.12.13-150000.3.6.1
python3-bottle - update to 0.12.13-150000.3.6.1
python2-bottle - update to 0.12.13-150000.3.6.1
python-bottle (Debian package) - addressed in versions 0.12.15-2+deb10u2, 0.12.19-1+deb11u1
python-bottle - addressed in versions 0.12.21-1.el8, 0.12.21-1.el9, 0.12.21-1.fc35, 0.12.21-2.el8, 0.12.21-2.el9, 0.12.21-2.fc35
IBM Cloud Pak for Data System - update to 1.0.8.2
IBM Integrated Analytics System - update to 1.0.28.0

External References

Related Security Bulletins