Fiche vulnérabilité
CVE-2021-29921 : faille critique python python (CVSS 9.8)
Description
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 6 mai 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- python python
- oracle communications cloud native core automated test suite
- oracle communications cloud native core binding support function
- oracle communications cloud native core network slice selection function
- oracle graalvm
- oracle zfs storage appliance kit
Références
- Fiche CVE-2021-29921 sur le NVD (NIST)
- bugs.python.org/issue36384
- docs.python.org/3/library/ipaddress.html
- github.com/python/cpython/blob/63298930fb531ba2bb4f23bc3b…
- github.com/python/cpython/pull/12577
- github.com/python/cpython/pull/25099
- github.com/sickcodes
- github.com/sickcodes/security/blob/master/advisories/SICK…
- python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html
- security.gentoo.org/glsa/202305-02
- security.netapp.com/advisory/ntap-20210622-0003/
- sick.codes/sick-2021-014
- oracle.com//security-alerts/cpujul2021.html
- oracle.com/security-alerts/cpuapr2022.html
- oracle.com/security-alerts/cpujan2022.html
- oracle.com/security-alerts/cpujul2022.html