CVE-2014-3137: Input Validation

Published May 1, 2014
·
Updated

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

Other sources

Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.

GitHub

It was reported that the JSON content-type was not restrictive enough. Bottle treated "text/plain;application/json" as JSON, allowing attackers to bypass intended security mechanisms. From the upstream report, "For example Chrome will not allow cross-origin xmlhttprequests with the content type set to "application/json" but you can set it to "text/plain;application/json" instead and bottle will accept it.".

Upstream report: https://github.com/defnull/bottle/issues/616

Patches for master, 0.11, and 0.12, respectively:

https://github.com/defnull/bottle/commit/7c3226867d9005903e268fedd819389ab8c6336d https://github.com/defnull/bottle/commit/a3c7b6eba63f41968c78ea61a2dd1bf334cff4b0 https://github.com/defnull/bottle/commit/2589f5a808da9d0c2d153c379557e1a090acdf04

Red Hat

Affected Software

29 affected componentsFixes available
pip/bottle>=0.12.0<0.12.6
0.12.6
pip/bottle>=0.11.0<0.11.7
0.11.7
pip/bottle>=0.10.0<0.10.12
0.10.12
Bottlepy Bottle=0.10.0
Bottlepy Bottle=0.10.1
Bottlepy Bottle=0.10.2
Bottlepy Bottle=0.10.3
Bottlepy Bottle=0.10.4
Bottlepy Bottle=0.10.5
Bottlepy Bottle=0.10.6
Bottlepy Bottle=0.10.7
Bottlepy Bottle=0.10.8
Bottlepy Bottle=0.10.9
Bottlepy Bottle=0.10.10
Bottlepy Bottle=0.10.11
Bottlepy Bottle=0.11.0
Bottlepy Bottle=0.11.1
Bottlepy Bottle=0.11.2
Bottlepy Bottle=0.11.3
Bottlepy Bottle=0.11.4
Bottlepy Bottle=0.11.5
Bottlepy Bottle=0.11.6
Bottlepy Bottle=0.11.7
Bottlepy Bottle=0.12.0
Bottlepy Bottle=0.12.1
Bottlepy Bottle=0.12.2
Bottlepy Bottle=0.12.3
Bottlepy Bottle=0.12.4
Bottlepy Bottle=0.12.5

Event History

May 1, 2014
Data Sourced
via Red Hat·04:26 AM
DescriptionSeverityAffected Software
Oct 25, 2014
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 17, 2022
Advisory Published
04:19 AM

Frequently Asked Questions

1

What is the severity of CVE-2014-3137?

CVE-2014-3137 is considered moderate as it allows remote attackers to bypass access restrictions.

2

How do I fix CVE-2014-3137?

To fix CVE-2014-3137, upgrade Bottle to version 0.12.6, 0.11.7, or 0.10.12 or later.

3

Which versions of Bottle are affected by CVE-2014-3137?

CVE-2014-3137 affects Bottle versions 0.10.x prior to 0.10.12, 0.11.x prior to 0.11.7, and 0.12.x prior to 0.12.6.

4

What type of vulnerability is CVE-2014-3137?

CVE-2014-3137 is a content type validation vulnerability.

5

Can exploit CVE-2014-3137 result in unauthorized access?

Yes, exploit of CVE-2014-3137 can lead to unauthorized access by bypassing intended content type restrictions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203