Bugzilla – Bug 1200286
VUL-0: CVE-2022-31799: python-bottle: error mishandling during early request binding.
Last modified: 2022-09-07 08:42:17 UTC
CVE-2022-31799 Bottle before 0.12.20 mishandles errors during early request binding. Upstream fix: https://github.com/bottlepy/bottle/commit/e140e1b54da721a660f2eb9d58a106b7b3ff2f00 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-31799 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-31799 https://github.com/bottlepy/bottle/compare/0.12.19...0.12.20 https://github.com/bottlepy/bottle/commit/e140e1b54da721a660f2eb9d58a106b7b3ff2f00 https://github.com/bottlepy/bottle/commit/a2b0ee6bb4ce88895429ec4aca856616244c4c4c
Affected: - SUSE:SLE-15:Update/python-bottle v0.12.13
Patch submitted https://build.opensuse.org/request/show/990452
Reassigning. Matej, could you please submit to SUSE:SLE-15:Update? :)
(In reply to Thomas Leroy from comment #3) > Reassigning. > Matej, could you please submit to SUSE:SLE-15:Update? :) Just submitted a fix.
SUSE-SU-2022:3103-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1200286 CVE References: CVE-2022-31799 JIRA References: Sources used: openSUSE Leap 15.4 (src): python-bottle-0.12.13-150000.3.6.1 openSUSE Leap 15.3 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Manager Server 4.1 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Manager Retail Branch Server 4.1 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Manager Proxy 4.1 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Server for SAP 15 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Server 15-SP2-BCL (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Server 15-LTSS (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Module for Python2 15-SP3 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP4 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): python-bottle-0.12.13-150000.3.6.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): python-bottle-0.12.13-150000.3.6.1 SUSE Enterprise Storage 7 (src): python-bottle-0.12.13-150000.3.6.1 SUSE Enterprise Storage 6 (src): python-bottle-0.12.13-150000.3.6.1 SUSE CaaS Platform 4.0 (src): python-bottle-0.12.13-150000.3.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.