0.13.2
15 years ago
2 months ago
Known vulnerabilities in the bottle package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Denial of Service (DoS) due to mishandling of errors during early request binding. How to fix Denial of Service (DoS)? Upgrade | [,0.12.20) |
Affected versions of this package are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter. PoC
The server sees 3 parameters here: How to fix Web Cache Poisoning? Upgrade | [0,0.12.19) |
| [0.10.1,0.12.11) |
| [0.8,0.10.12)[0.11,0.11.7)[0.12,0.12.6) |