Уязвимость обхода контроля доступа по IP-адресам в библиотеке "ipaddress" в Python из-за некорректной обработки нулей в октетах
Описание
В библиотеке ipaddress
в Python до версии 3.9.5 наблюдается некорректная обработка начальных нулей в октетах строки IP-адреса. Это позволяет злоумышленникам в определённых ситуациях обойти контроль доступа, основанный на IP-адресах.
Затронутые версии ПО
- Python до версии 3.9.5
Тип уязвимости
Обход контроля доступа
Ссылки
- Issue TrackingPatchVendor Advisory
- Vendor Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchVendor Advisory
- Vendor Advisory
- Third Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
In Python before 3,9,5, the ipaddress library mishandles leading zero ...
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2