First published: Fri Apr 30 2021(Updated: )
A flaw was found in python-ipaddress. Improper input validation of octal strings in stdlib ipaddress allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many programs that rely on Python stdlib ipaddress. The highest threat from this vulnerability is to data integrity and system availability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/rh-python38-babel | <0:2.7.0-12.el7 | 0:2.7.0-12.el7 |
redhat/rh-python38-python | <0:3.8.11-2.el7 | 0:3.8.11-2.el7 |
redhat/rh-python38-python-cryptography | <0:2.8-5.el7 | 0:2.8-5.el7 |
redhat/rh-python38-python-jinja2 | <0:2.10.3-6.el7 | 0:2.10.3-6.el7 |
redhat/rh-python38-python-lxml | <0:4.4.1-7.el7 | 0:4.4.1-7.el7 |
redhat/rh-python38-python-pip | <0:19.3.1-2.el7 | 0:19.3.1-2.el7 |
redhat/rh-python38-python-urllib3 | <0:1.25.7-7.el7 | 0:1.25.7-7.el7 |
redhat/python | <3.9 | 3.9 |
Python Python | >=3.8.0<3.8.12 | |
Python Python | >=3.9.0<3.9.5 | |
Oracle Communications Cloud Native Core Automated Test Suite | =1.8.0 | |
Oracle Communications Cloud Native Core Binding Support Function | =1.11.0 | |
Oracle Communications Cloud Native Core Network Slice Selection Function | =1.8.0 | |
Oracle GraalVM | =20.3.2 | |
Oracle GraalVM | =21.1.0 | |
Oracle ZFS Storage Appliance Kit | =8.8 | |
debian/pypy3 | 7.3.5+dfsg-2+deb11u2 7.3.5+dfsg-2+deb11u3 7.3.11+dfsg-2+deb12u2 7.3.17+dfsg-2 | |
debian/python2.7 | 2.7.18-8+deb11u1 | |
debian/python3.9 | <=3.9.2-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID is CVE-2021-29921.
The severity of CVE-2021-29921 is critical.
CVE-2021-29921 allows unauthenticated remote attackers to perform SSRF, RFI, and LFI attacks on programs that rely on Python stdlib ipaddress.
To fix CVE-2021-29921, update to Python version 3.9.5 or later.
You can find more information about CVE-2021-29921 at the following references: [CVE-2021-29921](https://www.cve.org/CVERecord?id=CVE-2021-29921), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-29921), [Python Security](https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1957458), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:4160).