cbcvebase.
CVE-2024-4032
published 2024-06-17

CVE-2024-4032: The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This…

PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.03%
60.0th percentile
The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianpypy3< pypy3 7.3.18+dfsg-1 (forky)pypy3 7.3.18+dfsg-1 (forky)
debianpython2.7< pypy3 7.3.18+dfsg-1 (forky)pypy3 7.3.18+dfsg-1 (forky)
debianpython3.11< pypy3 7.3.18+dfsg-1 (forky)pypy3 7.3.18+dfsg-1 (forky)
debianpython3.13< pypy3 7.3.18+dfsg-1 (forky)pypy3 7.3.18+dfsg-1 (forky)
debianpython3.9< pypy3 7.3.18+dfsg-1 (forky)pypy3 7.3.18+dfsg-1 (forky)
msrcazl3_python3_3.12.3-5_on_azure_linux_3.0
msrcazl3_python3_3.12.9-1_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-9_on_azure_linux_3.0
msrccbl2_python3_3.9.19-13_on_cbl_mariner_2.0
msrccbl2_python3_3.9.19-6_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
python_software_foundationcpython< 3.8.203.8.20
python_software_foundationcpython>= 3.10.0 < 3.10.153.10.15
python_software_foundationcpython>= 3.11.0 < 3.11.103.11.10
python_software_foundationcpython>= 3.12.0 < 3.12.43.12.4
python_software_foundationcpython>= 3.13.0a1 < 3.13.0a63.13.0a6
python_software_foundationcpython>= 3.9.0 < 3.9.203.9.20

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.