First published: Wed Apr 28 2021(Updated: )
A flaw was found in python-babel. A path traversal vulnerability was found in how locale data files are checked and loaded within python-babel, allowing a local attacker to trick an application that uses python-babel to load a file outside of the intended locale directory. The highest threat from this vulnerability is to data confidentiality and integrity as well as service availability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/babel | <0:2.5.1-7.el8 | 0:2.5.1-7.el8 |
redhat/python27-babel | <0:0.9.6-10.el7 | 0:0.9.6-10.el7 |
redhat/python27-python | <0:2.7.18-3.el7 | 0:2.7.18-3.el7 |
redhat/python27-python-jinja2 | <0:2.6-16.el7 | 0:2.6-16.el7 |
redhat/python27-python-pygments | <0:1.5-5.el7 | 0:1.5-5.el7 |
redhat/rh-python38-babel | <0:2.7.0-12.el7 | 0:2.7.0-12.el7 |
redhat/rh-python38-python | <0:3.8.11-2.el7 | 0:3.8.11-2.el7 |
redhat/rh-python38-python-cryptography | <0:2.8-5.el7 | 0:2.8-5.el7 |
redhat/rh-python38-python-jinja2 | <0:2.10.3-6.el7 | 0:2.10.3-6.el7 |
redhat/rh-python38-python-lxml | <0:4.4.1-7.el7 | 0:4.4.1-7.el7 |
redhat/rh-python38-python-pip | <0:19.3.1-2.el7 | 0:19.3.1-2.el7 |
redhat/rh-python38-python-urllib3 | <0:1.25.7-7.el7 | 0:1.25.7-7.el7 |
debian/python-babel | 2.6.0+dfsg.1-1+deb10u1 2.8.0+dfsg.1-7 2.10.3-1 2.10.3-2 | |
debian/python-babel | <=2.6.0+dfsg.1-1<=2.8.0+dfsg.1-6 | 2.8.0+dfsg.1-7 2.6.0+dfsg.1-1+deb10u1 |
Pocoo Babel | <2.9.1 | |
Debian Debian Linux | =10.0 | |
pip/babel | <2.9.1 | 2.9.1 |
IBM QRadar SIEM | <=7.5 - 7.5.0 UP9 IF03 | |
IBM QRadar Incident Forensics | <=7.5 - 7.5.0 UP9 IF03 | |
Debian | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)