9.8

CVE-2021-29921

Exploit

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PythonPython Version >= 3.8.0 < 3.8.12
PythonPython Version >= 3.9.0 < 3.9.5
OracleGraalvm Version20.3.2 SwEditionenterprise
OracleGraalvm Version21.1.0 SwEditionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.79% 0.822
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P