7.8
CVSSv3

CVE-2021-42771

Published: 20/10/2021 Updated: 14/12/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Babel.Locale in Babel prior to 2.9.1 allows malicious users to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pocoo babel

debian debian linux 10.0

Vendor Advisories

It was discovered that missing input sanitising in Babel, a set of tools for internationalising Python applications, could result in the execution of arbitrary code For the oldstable distribution (buster), this problem has been fixed in version 260+dfsg1-1+deb10u1 We recommend that you upgrade your python-babel packages For the detailed secur ...
Synopsis Important: OpenShift Container Platform 4110 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4110 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Co ...
Synopsis Moderate: OpenShift Container Platform 4110 extras and security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4110 is now available withupdates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift Conta ...
Synopsis Important: Migration Toolkit for Containers (MTC) 174 security and bug fix update Type/Severity Security Advisory: Important Topic The Migration Toolkit for Containers (MTC) 174 is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) ba ...
BabelLocale in Babel before 291 allows attackers to load arbitrary locale dat files (containing serialized Python objects) via directory traversal, leading to code execution (CVE-2021-42771) ...
BabelLocale in Babel before 291 allows attackers to load arbitrary locale dat files (containing serialized Python objects) via directory traversal, leading to code execution (CVE-2021-42771) ...