CVE-2021-29921
published 2021-05-06CVE-2021-29921: In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.59%
93.1th percentile
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | < pypy3 7.3.8+dfsg-1 (bookworm) | pypy3 7.3.8+dfsg-1 (bookworm) |
| debian | python2.7 | < pypy3 7.3.8+dfsg-1 (bookworm) | pypy3 7.3.8+dfsg-1 (bookworm) |
| debian | python3.9 | < pypy3 7.3.8+dfsg-1 (bookworm) | pypy3 7.3.8+dfsg-1 (bookworm) |
| oracle | communications_cloud_native_core_automated_test_suite | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| python | python | >= 3.8.0 < 3.8.12 | 3.8.12 |
| python | python | >= 3.9.0 < 3.9.5 | 3.9.5 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 [HIGH] python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
GHSA-cxqv-r2cc-r9c9: Improper input validation of octal strings in Python stdlib ipaddress 3
ghsa_unreviewed·2022-05-24
CVE-2021-29921 [CRITICAL] CWE-20 GHSA-cxqv-r2cc-r9c9: Improper input validation of octal strings in Python stdlib ipaddress 3
Improper input validation of octal strings in Python stdlib ipaddress 3.10 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many programs that rely on Python stdlib ipaddress. IP address octects are left stripped instead of evaluated as valid IP addresses.
OSV
CVE-2021-29921: In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string
osv·2021-05-06·CVSS 9.8
CVE-2021-29921 [CRITICAL] CVE-2021-29921: In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-07-11·CVSS 7.6
CVE-2021-29921 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-14647)
Oracle
Oracle Oracle Communications Risk Matrix: BSF (Python) — CVE-2021-29921
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2021-29921 [CRITICAL] Oracle Oracle Communications Risk Matrix: BSF (Python) — CVE-2021-29921
Oracle Oracle Communications Risk Matrix: BSF (Python) vulnerability
CVE: CVE-2021-29921
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Risk Matrix: ATS Framework (Python) — CVE-2021-29921
vendor_oracle·2022-01-15·CVSS 4.9
CVE-2021-29921 [CRITICAL] Oracle Oracle Communications Risk Matrix: ATS Framework (Python) — CVE-2021-29921
Oracle Oracle Communications Risk Matrix: ATS Framework (Python) vulnerability
CVE: CVE-2021-29921
CVSS: 4.9
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Ubuntu
Python vulnerability
vendor_ubuntu·2021-10-04
CVE-2021-29921 Python vulnerability
Title: Python vulnerability
Summary: Python could allow unintended access to network services.
USN-4973-1 fixed this vulnerability previously, but it was re-introduced
in python3.8 in focal because of the SRU in LP: #1928057. This update fixes
the problem.
Original advisory details:
It was discovered that the Python stdlib ipaddress API incorrectly handled
octal strings. A remote attacker could possibly use this issue to perform a
wide variety of attacks, including bypassing certain access restrictions.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Java SE Risk Matrix: Python interpreter and runtime (CPython) — CVE-2021-29921
vendor_oracle·2021-07-15·CVSS 9.8
CVE-2021-29921 [CRITICAL] Oracle Oracle Java SE Risk Matrix: Python interpreter and runtime (CPython) — CVE-2021-29921
Oracle Oracle Java SE Risk Matrix: Python interpreter and runtime (CPython) vulnerability
CVE: CVE-2021-29921
CVSS: 9.8
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Ubuntu
Python vulnerability
vendor_ubuntu·2021-06-01
CVE-2021-29921 Python vulnerability
Title: Python vulnerability
Summary: Python could allow unintended access to network services.
It was discovered that the Python stdlib ipaddress API incorrectly handled
octal strings. A remote attacker could possibly use this issue to perform a
wide variety of attacks, including bypassing certain access restrictions.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-ipaddress: Improper input validation of octal strings
vendor_redhat·2021-04-30·CVSS 9.8
CVE-2021-29921 [CRITICAL] CWE-20 python-ipaddress: Improper input validation of octal strings
python-ipaddress: Improper input validation of octal strings
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
A flaw was found in python-ipaddress. Improper input validation of octal strings in stdlib ipaddress allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many programs that rely on Python stdlib ipaddress. The highest threat from this vulnerability is to data integrity and system availability.
Package: python-ipaddress (Red Hat Enterprise Linux 7) - Not affected
Package: python-pip (Red Hat Enterprise Linux 7) - Not affected
Package: python27:2.7/python-ipaddress (Red
Debian
CVE-2021-29921: pypy3 - In Python before 3,9,5, the ipaddress library mishandles leading zero characters...
vendor_debian·2021·CVSS 9.8
CVE-2021-29921 [CRITICAL] CVE-2021-29921: pypy3 - In Python before 3,9,5, the ipaddress library mishandles leading zero characters...
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
Scope: local
bookworm: resolved (fixed in 7.3.8+dfsg-1)
bullseye: resolved
forky: resolved (fixed in 7.3.8+dfsg-1)
sid: resolved (fixed in 7.3.8+dfsg-1)
trixie: resolved (fixed in 7.3.8+dfsg-1)
No detection rules found.
No public exploits indexed.
https://bugs.python.org/issue36384https://docs.python.org/3/library/ipaddress.htmlhttps://github.com/python/cpython/blob/63298930fb531ba2bb4f23bc3b915dbf1e17e9e1/Misc/NEWS.d/3.8.0a4.rsthttps://github.com/python/cpython/pull/12577https://github.com/python/cpython/pull/25099https://github.com/sickcodeshttps://github.com/sickcodes/security/blob/master/advisories/SICK-2021-014.mdhttps://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.htmlhttps://security.gentoo.org/glsa/202305-02https://security.netapp.com/advisory/ntap-20210622-0003/https://sick.codes/sick-2021-014https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://bugs.python.org/issue36384https://docs.python.org/3/library/ipaddress.htmlhttps://github.com/python/cpython/blob/63298930fb531ba2bb4f23bc3b915dbf1e17e9e1/Misc/NEWS.d/3.8.0a4.rsthttps://github.com/python/cpython/pull/12577https://github.com/python/cpython/pull/25099https://github.com/sickcodeshttps://github.com/sickcodes/security/blob/master/advisories/SICK-2021-014.mdhttps://lists.debian.org/debian-lts-announce/2024/12/msg00000.htmlhttps://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.htmlhttps://security.gentoo.org/glsa/202305-02https://security.netapp.com/advisory/ntap-20210622-0003/https://sick.codes/sick-2021-014https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-05-06
Published