High severity7.8NVD Advisory· Published May 26, 2023· Updated Jun 17, 2026
CVE-2023-22970
CVE-2023-22970
Description
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Bottles/Bottlesdescription
- Range: <51.0
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- github.com/bottlesdevs/Bottles/issues/2463nvdIssue TrackingVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/N24KI3O3FWGKJSLATY35ZM3CHSABJ6WE/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZJZEE4RAAK7OPVQNE4BOWUVQDVSZU6NJ/nvd
News mentions
0No linked articles in our index yet.