CVE-2023-22970
Summary
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
- LOW
- LOCAL
- HIGH
- UNCHANGED
- REQUIRED
- NONE
- HIGH
- HIGH
References
Advisory Timeline
- Published
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.