CVE-2022-31799: Critical severity bottle vulnerability
Published May 29, 2022
·Updated
Bottle before 0.12.20 mishandles errors during early request binding.
Affected Software
8 affected componentsFixes available
debian/python-bottle
0.12.15-2+deb10u20.12.19-1+deb11u10.12.23-1.10.12.25-1
pip/bottle<0.12.20
0.12.20
Bottlepy Bottle<0.12.20
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Remediation
Event History
May 29, 2022
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
Description
Jun 2, 2022
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 3, 2022
Advisory Published
12:01 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-31799?
CVE-2022-31799 has a medium severity rating due to the mishandling of errors that can lead to unexpected behaviors in applications.
2
How do I fix CVE-2022-31799?
To fix CVE-2022-31799, upgrade to Bottle version 0.12.20 or later.
3
What versions are affected by CVE-2022-31799?
CVE-2022-31799 affects Bottle versions prior to 0.12.20, including 0.12.15, 0.12.19, 0.12.23, and 0.12.25.
4
Which platforms are impacted by CVE-2022-31799?
CVE-2022-31799 impacts applications using Bottle on Debian and Fedora distributions.
5
Can CVE-2022-31799 be exploited remotely?
Yes, CVE-2022-31799 can potentially be exploited remotely if the application is publicly accessible and utilizes vulnerable Bottle versions.