{"id":"MGASA-2021-0171","summary":"Updated python-bottle packages fix security vulnerability","details":"Updated python-bottle packages fix security vulnerability:\n\npython-bottle before 0.12.19 is vulnerable to Web Cache Poisoning by using\na vector called parameter cloaking. When the attacker can separate query\nparameters using a semicolon (;), they can cause a difference in the\ninterpretation of the request between the proxy (running with default\nconfiguration) and the server. This can result in malicious requests being\ncached as completely safe ones, as the proxy would usually not see the\nsemicolon as a separator, and therefore would not include it in a cache key\nof an unkeyed parameter (CVE-2020-28473).\n","modified":"2026-04-16T04:43:18.764090137Z","published":"2021-04-02T20:25:05Z","upstream":["CVE-2020-28473"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0171.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28219"},{"type":"WEB","url":"https://www.debian.org/lts/security/2021/dla-2531"}],"affected":[{"package":{"name":"python-bottle","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/python-bottle?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.12.16-1.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0171.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}