cbcvebase.
CVE-2021-29921
published 2021-05-06

CVE-2021-29921: In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianpypy3< pypy3 7.3.8+dfsg-1 (bookworm)pypy3 7.3.8+dfsg-1 (bookworm)
debianpython2.7< pypy3 7.3.8+dfsg-1 (bookworm)pypy3 7.3.8+dfsg-1 (bookworm)
debianpython3.9< pypy3 7.3.8+dfsg-1 (bookworm)pypy3 7.3.8+dfsg-1 (bookworm)
oraclecommunications_cloud_native_core_automated_test_suite
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_network_slice_selection_function
oraclegraalvm
oraclegraalvm
oraclezfs_storage_appliance_kit
pythonpython>= 3.8.0 < 3.8.123.8.12
pythonpython>= 3.9.0 < 3.9.53.9.5

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL