Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-29921

Опубликовано: 30 апр. 2021
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

A flaw was found in python-ipaddress. Improper input validation of octal strings in stdlib ipaddress allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many programs that rely on Python stdlib ipaddress. The highest threat from this vulnerability is to data integrity and system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7python-ipaddressNot affected
Red Hat Enterprise Linux 7python-pipNot affected
Red Hat Enterprise Linux 8python27:2.7/python-ipaddressNot affected
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Software Collectionspython27-python-pipNot affected
Red Hat Software Collectionsrh-python36-pythonNot affected
Red Hat Enterprise Linux 8python39FixedRHSA-2021:416009.11.2021
Red Hat Enterprise Linux 8python39-develFixedRHSA-2021:416009.11.2021
Red Hat Enterprise Linux 8python38FixedRHSA-2021:416209.11.2021
Red Hat Enterprise Linux 8python38-develFixedRHSA-2021:416209.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1957458python-ipaddress: Improper input validation of octal strings

EPSS

Процентиль: 82%
0.01887
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
nvd
около 4 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 9.8
debian
около 4 лет назад

In Python before 3,9,5, the ipaddress library mishandles leading zero ...

suse-cvrf
почти 4 года назад

Security update for python39

suse-cvrf
почти 4 года назад

Security update for python39

EPSS

Процентиль: 82%
0.01887
Низкий

9.1 Critical

CVSS3