cbcvebase.
CVE-2021-29921
published 2021-05-06

CVE-2021-29921: In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows…

PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
6.59%
93.1th percentile
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianpypy3< pypy3 7.3.8+dfsg-1 (bookworm)pypy3 7.3.8+dfsg-1 (bookworm)
debianpython2.7< pypy3 7.3.8+dfsg-1 (bookworm)pypy3 7.3.8+dfsg-1 (bookworm)
debianpython3.9< pypy3 7.3.8+dfsg-1 (bookworm)pypy3 7.3.8+dfsg-1 (bookworm)
oraclecommunications_cloud_native_core_automated_test_suite
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_network_slice_selection_function
oraclegraalvm
oraclegraalvm
oraclezfs_storage_appliance_kit
pythonpython>= 3.8.0 < 3.8.123.8.12
pythonpython>= 3.9.0 < 3.9.53.9.5

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.