Security features bypass in Bottle - CVE-2022-31799
Published: June 1, 2022
Vulnerability identifier: #VU63912
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-31799
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to mishandling errors during early request binding. A remote attacker can exploit this vulnerability to launch further attacks on the system.
Affected software
Bottle
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Fedora
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Python for Scientific Computing
Splunk Universal Forwarder
Splunk Enterprise
python3-bottle (Ubuntu package)
python-bottle (Ubuntu package)
python2-bottle
python3-bottle
python-bottle
python-bottle-doc
python-bottle (Debian package)
IBM Cloud Pak for Data System
IBM Integrated Analytics System
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
SUSE Linux Enterprise Storage
Fedora
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Python for Scientific Computing
Splunk Universal Forwarder
Splunk Enterprise
python3-bottle (Ubuntu package)
python-bottle (Ubuntu package)
python2-bottle
python3-bottle
python-bottle
python-bottle-doc
python-bottle (Debian package)
IBM Cloud Pak for Data System
IBM Integrated Analytics System
How to mitigate CVE-2022-31799
Install updates from vendor's website.
Bottle - update to 0.12.20
Python for Scientific Computing - update to 4.2.1
Splunk Universal Forwarder - addressed in versions 9.0.7, 9.1.2
Splunk Enterprise - addressed in versions 9.0.7, 9.1.2
python3-bottle (Ubuntu package) - addressed in versions 0.12.13-1ubuntu0.2, 0.12.15-2.1ubuntu0.2, 0.12.19-1+deb11u1build0.22.04.1
python-bottle (Ubuntu package) - update to 0.12.13-1ubuntu0.2
python2-bottle - update to 0.12.13-9
python3-bottle - update to 0.12.13-9
python-bottle - update to 0.12.13-9
python-bottle-doc - update to 0.12.13-150000.3.6.1
python3-bottle - update to 0.12.13-150000.3.6.1
python2-bottle - update to 0.12.13-150000.3.6.1
python-bottle (Debian package) - addressed in versions 0.12.15-2+deb10u2, 0.12.19-1+deb11u1
python-bottle - addressed in versions 0.12.21-1.el8, 0.12.21-1.el9, 0.12.21-1.fc35, 0.12.21-2.el8, 0.12.21-2.el9, 0.12.21-2.fc35
IBM Cloud Pak for Data System - update to 1.0.8.2
IBM Integrated Analytics System - update to 1.0.28.0
Python for Scientific Computing - update to 4.2.1
Splunk Universal Forwarder - addressed in versions 9.0.7, 9.1.2
Splunk Enterprise - addressed in versions 9.0.7, 9.1.2
python3-bottle (Ubuntu package) - addressed in versions 0.12.13-1ubuntu0.2, 0.12.15-2.1ubuntu0.2, 0.12.19-1+deb11u1build0.22.04.1
python-bottle (Ubuntu package) - update to 0.12.13-1ubuntu0.2
python2-bottle - update to 0.12.13-9
python3-bottle - update to 0.12.13-9
python-bottle - update to 0.12.13-9
python-bottle-doc - update to 0.12.13-150000.3.6.1
python3-bottle - update to 0.12.13-150000.3.6.1
python2-bottle - update to 0.12.13-150000.3.6.1
python-bottle (Debian package) - addressed in versions 0.12.15-2+deb10u2, 0.12.19-1+deb11u1
python-bottle - addressed in versions 0.12.21-1.el8, 0.12.21-1.el9, 0.12.21-1.fc35, 0.12.21-2.el8, 0.12.21-2.el9, 0.12.21-2.fc35
IBM Cloud Pak for Data System - update to 1.0.8.2
IBM Integrated Analytics System - update to 1.0.28.0
External References
Related Security Bulletins
- Security features bypass in Bottle
- Debian update for python-bottle
- Ubuntu update for python-bottle
- SUSE update for python-bottle
- Multiple vulnerabilities in IBM Integrated Analytics System
- Security features bypass in IBM Cloud Pak for Data System
- Splunk Enterprise update for third-party components
- Splunk Universal Forwarder update for third-party components
- openEuler update for python-bottle
- Splunk Python for Scientific Computing update for third-party packages
- Fedora EPEL 9 update for python-bottle
- Fedora EPEL 8 update for python-bottle
- Fedora 35 update for python-bottle
- Fedora 35 update for python-bottle
- Fedora EPEL 9 update for python-bottle
- Fedora EPEL 8 update for python-bottle