CVE-2021-29921
🔴 Łataj teraz
Błąd w bibliotece ipaddress w Pythonie umożliwia obejście kontroli dostępu opartej na adresach IP.
CVSS
9.8
EPSS
6.9%
Exploit
poc
Vendor
oracle
Opis źródłowy (NVD)
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 6.9% |
| Opublikowano (NVD) | 2021-05-06 13:15:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:17:09 UTC |
Referencje
- https://bugs.python.org/issue36384 ([email protected]) [Issue Tracking, Patch, Vendor Advisory]
- https://docs.python.org/3/library/ipaddress.html ([email protected]) [Vendor Advisory]
- https://github.com/python/cpython/blob/63298930fb531ba2bb4f23bc3b915dbf1e17e9e1/Misc/NEWS.d/3.8.0a4.rst ([email protected]) [Third Party Advisory]
- https://github.com/python/cpython/pull/12577 ([email protected]) [Patch, Third Party Advisory]
- https://github.com/python/cpython/pull/25099 ([email protected]) [Patch, Third Party Advisory]
- https://github.com/sickcodes ([email protected]) [Third Party Advisory]
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-014.md ([email protected]) [Exploit, Third Party Advisory]
- https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html ([email protected]) [Vendor Advisory]
- https://security.gentoo.org/glsa/202305-02 ([email protected])
- https://security.netapp.com/advisory/ntap-20210622-0003/ ([email protected]) [Third Party Advisory]
- https://sick.codes/sick-2021-014 ([email protected]) [Exploit, Third Party Advisory]
- https://www.oracle.com//security-alerts/cpujul2021.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuapr2022.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujan2022.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujul2022.html ([email protected])
- https://www.oracle.com/security-alerts/cpuoct2021.html ([email protected]) [Patch, Third Party Advisory]
- https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html (af854a3a-2127-422b-91ae-364da2661108)