CVE-2021-20095

Related Vulnerabilities: CVE-2021-20095  

Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code.

Description

The MITRE CVE dictionary describes this issue as:

Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code.

Additional Information

  • Bugzilla 1955615: CVE-2021-20095 python-babel: relative path traversal allows an attacker to load arbitrary locale files on disk and execute arbitrary code
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • FAQ: Frequently asked questions about CVE-2021-20095