CVE Vulnerabilities

CVE-2021-29921

Published: May 06, 2021 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
9.1 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Ubuntu
MEDIUM

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

Affected Software

Name Vendor Start Version End Version
Python Python 3.8.0 (including) 3.8.12 (excluding)
Python Python 3.9.0 (including) 3.9.5 (excluding)
Red Hat Enterprise Linux 8 RedHat python39:3.9-8050020210811100211.d428a79b *
Red Hat Enterprise Linux 8 RedHat python39-devel:3.9-8050020210811100211.d428a79b *
Red Hat Enterprise Linux 8 RedHat python38:3.8-8050020210811101222.e3d35cca *
Red Hat Enterprise Linux 8 RedHat python38-devel:3.8-8050020210811101222.e3d35cca *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python38-babel-0:2.7.0-12.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python38-python-0:3.8.11-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python38-python-cryptography-0:2.8-5.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python38-python-jinja2-0:2.10.3-6.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python38-python-lxml-0:4.4.1-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python38-python-pip-0:19.3.1-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python38-python-urllib3-0:1.25.7-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-python38-babel-0:2.7.0-12.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-python38-python-0:3.8.11-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-python38-python-cryptography-0:2.8-5.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-python38-python-jinja2-0:2.10.3-6.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-python38-python-lxml-0:4.4.1-7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-python38-python-pip-0:19.3.1-2.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS RedHat rh-python38-python-urllib3-0:1.25.7-7.el7 *
Python2.7 Ubuntu trusty *
Python3.10 Ubuntu hirsute *
Python3.4 Ubuntu trusty *
Python3.5 Ubuntu trusty *
Python3.8 Ubuntu bionic *
Python3.8 Ubuntu esm-apps/bionic *
Python3.8 Ubuntu focal *
Python3.8 Ubuntu groovy *
Python3.9 Ubuntu focal *
Python3.9 Ubuntu groovy *
Python3.9 Ubuntu hirsute *
Python3.9 Ubuntu impish *

References