Python — высокоуровневый язык программирования общего назначения. Его философия дизайна делает акцент на читаемости кода.
Релизный цикл, информация об уязвимостях
График релизов
Количество 1 104
BDU:2022-05830
Уязвимость компонента urllib интерпретатора языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании
CVE-2021-29921
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
CVE-2022-0391
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.
SUSE-SU-2021:0947-1
Security update for python3
ELSA-2021-9129
ELSA-2021-9129: python36:3.6 security update (IMPORTANT)
ELSA-2021-9130
ELSA-2021-9130: python38:3.8 security update (IMPORTANT)
ELSA-2021-9128
ELSA-2021-9128: python27:2.7 security update (IMPORTANT)
SUSE-SU-2021:0887-1
Security update for python36
SUSE-SU-2021:0886-1
Security update for python3
CVE-2021-28667
StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data (from an action or rule name).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
BDU:2022-05830 Уязвимость компонента urllib интерпретатора языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 12% Средний | около 5 лет назад | |
CVE-2021-29921 In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses. | CVSS3: 9.1 | 7% Низкий | больше 5 лет назад | |
CVE-2022-0391 A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14. | CVSS3: 5.3 | 8% Низкий | больше 5 лет назад | |
SUSE-SU-2021:0947-1 Security update for python3 | 36% Средний | больше 5 лет назад | ||
ELSA-2021-9129 ELSA-2021-9129: python36:3.6 security update (IMPORTANT) | 23% Средний | больше 5 лет назад | ||
ELSA-2021-9130 ELSA-2021-9130: python38:3.8 security update (IMPORTANT) | 23% Средний | больше 5 лет назад | ||
ELSA-2021-9128 ELSA-2021-9128: python27:2.7 security update (IMPORTANT) | 23% Средний | больше 5 лет назад | ||
SUSE-SU-2021:0887-1 Security update for python36 | 36% Средний | больше 5 лет назад | ||
SUSE-SU-2021:0886-1 Security update for python3 | 36% Средний | больше 5 лет назад | ||
CVE-2021-28667 StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. This can occur if Python 3.x is used, the locale is not utf-8, and there is an attempt to log Unicode data (from an action or rule name). | CVSS3: 7.5 | 2% Низкий | больше 5 лет назад |
Уязвимостей на страницу