CVE Vulnerabilities

CVE-2021-29921

Published: May 06, 2021 | Modified: Nov 03, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
9.1 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

Affected Software

NameVendorStart VersionEnd Version
PythonPython3.8.0 (including)3.8.12 (excluding)
PythonPython3.9.0 (including)3.9.5 (excluding)
Red Hat Enterprise Linux 8RedHatpython39:3.9-8050020210811100211.d428a79b*
Red Hat Enterprise Linux 8RedHatpython39-devel:3.9-8050020210811100211.d428a79b*
Red Hat Enterprise Linux 8RedHatpython38:3.8-8050020210811101222.e3d35cca*
Red Hat Enterprise Linux 8RedHatpython38-devel:3.8-8050020210811101222.e3d35cca*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python38-babel-0:2.7.0-12.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python38-python-0:3.8.11-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python38-python-cryptography-0:2.8-5.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python38-python-jinja2-0:2.10.3-6.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python38-python-lxml-0:4.4.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python38-python-pip-0:19.3.1-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python38-python-urllib3-0:1.25.7-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-python38-babel-0:2.7.0-12.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-python38-python-0:3.8.11-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-python38-python-cryptography-0:2.8-5.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-python38-python-jinja2-0:2.10.3-6.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-python38-python-lxml-0:4.4.1-7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-python38-python-pip-0:19.3.1-2.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUSRedHatrh-python38-python-urllib3-0:1.25.7-7.el7*
Python2.7Ubuntutrusty*
Python3.10Ubuntuhirsute*
Python3.4Ubuntutrusty*
Python3.5Ubuntutrusty*
Python3.8Ubuntubionic*
Python3.8Ubuntuesm-apps/bionic*
Python3.8Ubuntuesm-infra/focal*
Python3.8Ubuntufocal*
Python3.8Ubuntugroovy*
Python3.9Ubuntuesm-apps/focal*
Python3.9Ubuntufocal*
Python3.9Ubuntugroovy*
Python3.9Ubuntuhirsute*
Python3.9Ubuntuimpish*

References