6.5
CVE-2021-3733
- EPSS 4.68%
- Veröffentlicht 10.03.2022 17:42:59
- Zuletzt bearbeitet 03.11.2025 22:15:50
- Erkennungen
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Codeready Linux Builder Version 8.0
Redhat ≫ Codeready Linux Builder For Ibm Z Systems Version 8.0
Redhat ≫ Codeready Linux Builder For Power Little Endian Version 8.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux For Ibm Z Systems Version 8.0
Redhat ≫ Enterprise Linux For Ibm Z Systems Eus Version 8.4
Redhat ≫ Enterprise Linux For Power Little Endian Version 8.0
Redhat ≫ Enterprise Linux For Power Little Endian Eus Version 8.4
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server For Power Little Endian Update Services For Sap Solutions Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Fedoraproject ≫ Extra Packages For Enterprise Linux Version 7.0
Fedoraproject ≫ Fedora Version 33
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Netapp ≫ Ontap Select Deploy Administration Utility Version -
Netapp ≫ Hci Compute Node Firmware Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.68% | 0.908 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:P
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
https://bugs.python.org/issue43075
https://bugzilla.redhat.com/show_bug.cgi?id=1995234
https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb
https://github.com/python/cpython/pull/24391
https://security.netapp.com/advisory/ntap-20220407-0001/
https://ubuntu.com/security/CVE-2021-3733
https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html