ALAS2022-2022-205


Amazon Linux 2022 Security Advisory: ALAS-2022-205
Advisory Release Date: 2022-11-01 21:25 Pacific
Advisory Updated Date: 2022-11-03 20:54 Pacific
Severity: Important

Issue Overview:

Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.2. (CVE-2022-3179)

Bottle before 0.12.20 mishandles errors during early request binding. (CVE-2022-31799)


Affected Packages:

python-bottle


Issue Correction:
Run dnf update python-bottle --releasever=2022.0.20221102 to update your system.

New Packages:
noarch:
    python3-bottle-0.12.21-2.amzn2022.noarch

src:
    python-bottle-0.12.21-2.amzn2022.src