Aller au contenu

Fiche vulnérabilité

CVE-2021-29921 : faille critique python python (CVSS 9.8)

Description

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
6 mai 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • python python
  • oracle communications cloud native core automated test suite
  • oracle communications cloud native core binding support function
  • oracle communications cloud native core network slice selection function
  • oracle graalvm
  • oracle zfs storage appliance kit

Références

Rechercher une autre vulnérabilité dans la base CVE