CVE-2023-22970: High severity bottles vulnerability
Published May 26, 2023
·Updated
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
Affected Software
3 affected components
Usebottles Bottles<51.0
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Event History
May 26, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-22970?
CVE-2023-22970 is a vulnerability in Bottles before version 51.0 that allows remote code execution via a crafted file.
2
How does Bottles mishandle YAML load in CVE-2023-22970?
Bottles mishandles YAML load, allowing remote code execution when a crafted file is processed.
3
Which software versions are affected by CVE-2023-22970?
Bottles versions up to (but not including) 51.0 are affected by CVE-2023-22970.
4
What is the severity of CVE-2023-22970?
CVE-2023-22970 has a high severity with a CVSS score of 7.
5
How can I fix CVE-2023-22970?
Upgrade Bottles to version 51.0 or above to fix CVE-2023-22970.