Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Mageia 7: MGASA-2021-0171 Moderate: python-bottle Web Cache Poisoning

mageia
Calendar Grey April 2, 2021
Dist Mageia Esm H88
Recent upgrades to the python-bottle packages address a significant web cache poisoning vulnerability, improving the security posture of Mageia.
Updated python-bottle packages fix security vulnerability: python-bottle before 0.12.19 is vulnerable to Web Cache Poisoning by using a vector called parameter cloaking

Summary

Updated python-bottle packages fix security vulnerability:
python-bottle before 0.12.19 is vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter (CVE-2020-28473).

References

- https://bugs.mageia.org/show_bug.cgi?id=28219

- https://lists.debian.org/debian-lts-announce/2021/01/msg00019.html

- https://www.cve.org/CVERecord?id=CVE-2020-28473

Resolution

SRPMS

- 7/core/python-bottle-0.12.16-1.1.mga7

Publication date: 02 Apr 2021
URL: https://advisories.mageia.org/MGASA-2021-0171.html
Type: security
CVE: CVE-2020-28473

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here