{"id":"CVE-2014-3137","details":"Bottle 0.10.x before 0.10.12, 0.11.x before 0.11.7, and 0.12.x before 0.12.6 does not properly limit content types, which allows remote attackers to bypass intended access restrictions via an accepted Content-Type followed by a ; (semi-colon) and a Content-Type that would not be accepted, as demonstrated in YouCompleteMe to execute arbitrary code.","aliases":["GHSA-873q-wpqr-xfgw","PYSEC-2014-77"],"modified":"2026-04-10T03:44:38.578978Z","published":"2014-10-25T22:55:04Z","references":[{"type":"ADVISORY","url":"http://www.debian.org/security/2014/dsa-2948"},{"type":"ADVISORY","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1093255"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1093255"},{"type":"REPORT","url":"https://github.com/defnull/bottle/issues/616"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/05/01/15"}],"schema_version":"1.7.5"}