First published: Fri May 26 2023(Updated: )
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usebottles Bottles | <51.0 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22970 is a vulnerability in Bottles before version 51.0 that allows remote code execution via a crafted file.
Bottles mishandles YAML load, allowing remote code execution when a crafted file is processed.
Bottles versions up to (but not including) 51.0 are affected by CVE-2023-22970.
CVE-2023-22970 has a high severity with a CVSS score of 7.
Upgrade Bottles to version 51.0 or above to fix CVE-2023-22970.