Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.1.10.2021.0171
Categoría:Mageia Linux Local Security Checks
Título:Mageia: Security Advisory (MGASA-2021-0171)
Resumen:The remote host is missing an update for the 'python-bottle' package(s) announced via the MGASA-2021-0171 advisory.
Descripción:Summary:
The remote host is missing an update for the 'python-bottle' package(s) announced via the MGASA-2021-0171 advisory.

Vulnerability Insight:
Updated python-bottle packages fix security vulnerability:

python-bottle before 0.12.19 is vulnerable to Web Cache Poisoning by using
a vector called parameter cloaking. When the attacker can separate query
parameters using a semicolon (,), they can cause a difference in the
interpretation of the request between the proxy (running with default
configuration) and the server. This can result in malicious requests being
cached as completely safe ones, as the proxy would usually not see the
semicolon as a separator, and therefore would not include it in a cache key
of an unkeyed parameter (CVE-2020-28473).

Affected Software/OS:
'python-bottle' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2020-28473
https://github.com/bottlepy/bottle
https://snyk.io/vuln/SNYK-PYTHON-BOTTLE-1017108
https://lists.debian.org/debian-lts-announce/2021/01/msg00019.html
CopyrightCopyright (C) 2022 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.