var-202109-1966
Vulnerability from variot
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability. Python Software Foundation of Python Products from other vendors have resource exhaustion vulnerabilities.Service operation interruption (DoS) It may be in a state. Python is an open source, object-oriented programming language developed by the Python Foundation. The language is scalable, supports modules and packages, and supports multiple platforms. A code issue vulnerability exists in Python due to a failure in the product to properly handle RCFS. An attacker could exploit this vulnerability to cause a denial of service. The following products and versions are affected: python3.5 For Ubuntu 16.04 ESM. ========================================================================== Ubuntu Security Notice USN-5200-1 December 17, 2021
python3.7, python3.8 vulnerabilities
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
Python could be made to crash if it receives specially crafted input from a malicious server. (CVE-2020-8492)
It was discovered that the urllib.request.AbstractBasicAuthHandler class in Python contains regex with a quadratic worst-case time complexity. (CVE-2021-3737)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04 LTS: libpython3.7-stdlib 3.7.5-2ubuntu1~18.04.2 libpython3.8-stdlib 3.8.0-3ubuntu1~18.04.2 python3.7 3.7.5-2ubuntu1~18.04.2 python3.7-minimal 3.7.5-2ubuntu1~18.04.2 python3.8 3.8.0-3ubuntu1~18.04.2 python3.8-minimal 3.8.0-3ubuntu1~18.04.2
In general, a standard system update will make all the necessary changes. Bugs fixed (https://bugzilla.redhat.com/):
1983596 - CVE-2021-34558 golang: crypto/tls: certificate of wrong type is causing TLS client to panic 1992006 - CVE-2021-29923 golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet 1997017 - unprivileged client fails to get guest agent data 1998855 - Node drain: Sometimes source virt-launcher pod status is Failed and not Completed 2000251 - RoleBinding and ClusterRoleBinding brought in by kubevirt does not get reconciled when kind is ServiceAccount 2001270 - [VMIO] [Warm from Vmware] Snapshot files are not deleted after Successful Import 2001281 - [VMIO] [Warm from VMware] Source VM should not be turned ON if vmio import is removed 2001901 - [4.8.3] NNCP creation failures after nmstate-handler pod deletion 2007336 - 4.8.3 containers 2007776 - Failed to Migrate Windows VM with CDROM (readonly) 2008511 - [CNV-4.8.3] VMI is in LiveMigrate loop when Upgrading Cluster from 2.6.7/4.7.32 to OCP 4.8.13 2012890 - With descheduler during multiple VMIs migrations, some VMs are restarted 2025475 - [4.8.3] Upgrade from 2.6 to 4.x versions failed due to vlan-filtering issues 2026881 - [4.8.3] vlan-filtering is getting applied on veth ports
- Summary:
The Migration Toolkit for Containers (MTC) 1.5.2 is now available. Description:
The Migration Toolkit for Containers (MTC) enables you to migrate Kubernetes resources, persistent volume data, and internal container images between OpenShift Container Platform clusters, using the MTC web console or the Kubernetes API. Bugs fixed (https://bugzilla.redhat.com/):
2000734 - CVE-2021-3757 nodejs-immer: prototype pollution may lead to DoS or remote code execution 2005438 - Combining Rsync and Stunnel in a single pod can degrade performance (1.5 backport) 2006842 - MigCluster CR remains in "unready" state and source registry is inaccessible after temporary shutdown of source cluster 2007429 - "oc describe" and "oc log" commands on "Migration resources" tree cannot be copied after failed migration 2022017 - CVE-2021-3948 mig-controller: incorrect namespaces handling may lead to not authorized usage of Migration Toolkit for Containers (MTC)
- -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256
===================================================================== Red Hat Security Advisory
Synopsis: Moderate: python3 security update Advisory ID: RHSA-2021:4057-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:4057 Issue date: 2021-11-02 CVE Names: CVE-2021-3733 =====================================================================
- Summary:
An update for python3 is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
- Relevant releases/architectures:
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64
- Description:
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.
Security Fix(es):
- python: urllib: Regular expression DoS in AbstractBasicAuthHandler (CVE-2021-3733)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
- Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258
- Bugs fixed (https://bugzilla.redhat.com/):
1995234 - CVE-2021-3733 python: urllib: Regular expression DoS in AbstractBasicAuthHandler
- Package List:
Red Hat Enterprise Linux AppStream (v. 8):
aarch64: platform-python-debug-3.6.8-39.el8_4.aarch64.rpm platform-python-devel-3.6.8-39.el8_4.aarch64.rpm python3-debuginfo-3.6.8-39.el8_4.aarch64.rpm python3-debugsource-3.6.8-39.el8_4.aarch64.rpm python3-idle-3.6.8-39.el8_4.aarch64.rpm python3-tkinter-3.6.8-39.el8_4.aarch64.rpm
ppc64le: platform-python-debug-3.6.8-39.el8_4.ppc64le.rpm platform-python-devel-3.6.8-39.el8_4.ppc64le.rpm python3-debuginfo-3.6.8-39.el8_4.ppc64le.rpm python3-debugsource-3.6.8-39.el8_4.ppc64le.rpm python3-idle-3.6.8-39.el8_4.ppc64le.rpm python3-tkinter-3.6.8-39.el8_4.ppc64le.rpm
s390x: platform-python-debug-3.6.8-39.el8_4.s390x.rpm platform-python-devel-3.6.8-39.el8_4.s390x.rpm python3-debuginfo-3.6.8-39.el8_4.s390x.rpm python3-debugsource-3.6.8-39.el8_4.s390x.rpm python3-idle-3.6.8-39.el8_4.s390x.rpm python3-tkinter-3.6.8-39.el8_4.s390x.rpm
x86_64: platform-python-3.6.8-39.el8_4.i686.rpm platform-python-debug-3.6.8-39.el8_4.i686.rpm platform-python-debug-3.6.8-39.el8_4.x86_64.rpm platform-python-devel-3.6.8-39.el8_4.i686.rpm platform-python-devel-3.6.8-39.el8_4.x86_64.rpm python3-debuginfo-3.6.8-39.el8_4.i686.rpm python3-debuginfo-3.6.8-39.el8_4.x86_64.rpm python3-debugsource-3.6.8-39.el8_4.i686.rpm python3-debugsource-3.6.8-39.el8_4.x86_64.rpm python3-idle-3.6.8-39.el8_4.i686.rpm python3-idle-3.6.8-39.el8_4.x86_64.rpm python3-test-3.6.8-39.el8_4.i686.rpm python3-tkinter-3.6.8-39.el8_4.i686.rpm python3-tkinter-3.6.8-39.el8_4.x86_64.rpm
Red Hat Enterprise Linux BaseOS (v. 8):
Source: python3-3.6.8-39.el8_4.src.rpm
aarch64: platform-python-3.6.8-39.el8_4.aarch64.rpm python3-debuginfo-3.6.8-39.el8_4.aarch64.rpm python3-debugsource-3.6.8-39.el8_4.aarch64.rpm python3-libs-3.6.8-39.el8_4.aarch64.rpm python3-test-3.6.8-39.el8_4.aarch64.rpm
ppc64le: platform-python-3.6.8-39.el8_4.ppc64le.rpm python3-debuginfo-3.6.8-39.el8_4.ppc64le.rpm python3-debugsource-3.6.8-39.el8_4.ppc64le.rpm python3-libs-3.6.8-39.el8_4.ppc64le.rpm python3-test-3.6.8-39.el8_4.ppc64le.rpm
s390x: platform-python-3.6.8-39.el8_4.s390x.rpm python3-debuginfo-3.6.8-39.el8_4.s390x.rpm python3-debugsource-3.6.8-39.el8_4.s390x.rpm python3-libs-3.6.8-39.el8_4.s390x.rpm python3-test-3.6.8-39.el8_4.s390x.rpm
x86_64: platform-python-3.6.8-39.el8_4.x86_64.rpm python3-debuginfo-3.6.8-39.el8_4.i686.rpm python3-debuginfo-3.6.8-39.el8_4.x86_64.rpm python3-debugsource-3.6.8-39.el8_4.i686.rpm python3-debugsource-3.6.8-39.el8_4.x86_64.rpm python3-libs-3.6.8-39.el8_4.i686.rpm python3-libs-3.6.8-39.el8_4.x86_64.rpm python3-test-3.6.8-39.el8_4.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/
- References:
https://access.redhat.com/security/cve/CVE-2021-3733 https://access.redhat.com/security/updates/classification/#moderate
- Contact:
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1
iQIVAwUBYYD6u9zjgjWX9erEAQgCbg//S3byb5BXGosk0v+LDiREjmiOkmk9QpLJ 8SCgT7ap9IRI6rghoGv7bsLpRyydrd8KR0pIDCQOJngEGZfJEUiwk6QhdFs0JHqG aHb1JJCBGTyQ9b0jhrKlJKCvJJk9oscRhkVn2AYm9r4fAnwzSqLaTd+8/PxJrKi+ 7M6I3xh3MYVj5j8Y56GCXYbuAxQqNRPUunzLC8tr79zuVt1iH5qAbff/Dmtkpl4A zDDMp42s7UN1H+Y4pRo9b7MqJLpa1GjuZWsVr53QZu4al7Cbw+iAlz4R2P3pQVKv uHCkl7pWi+v22po5C55+djkPPzzu0NiVJ9CLI/gtI4lx7dJ6uKqNaPvetzuaKaR5 9HEFIRat1V/jD/boAa4gUscosId8h8Arm8UDLaIoJ5IqdNYrRb+AtXpBN2Clg0S2 z9KLbG7jNFAH4sqmIsYz2t+O8pQteMzQdbhoSx8KdaQgIqjUBd+dBXE3P0kndc0g 1No7qsDjavlD31uvXC6K+RO0bESW7kZbcscseO5xiiMNBCbWjKVjKo5DavNxmrTf W4DkMsSzmijKqBsoBgxizFiCF82NH+UXIY/PSNJ4h8KKwi377FRwVvjg8JC5TBPG Wpg6oNbHBTrWEmdlOcL6C13gjIDVtU3lWVomlGYkb7/t4KtjiorJuzuolcqpkRVp YfBN+OdHhpA= =MOG7 -----END PGP SIGNATURE-----
-- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce . This version of the OpenShift Serverless Operator is supported on Red Hat OpenShift Container Platform versions 4.6, 4.7, 4.8 and 4.9, and includes security and bug fixes and enhancements. Bugs fixed (https://bugzilla.redhat.com/):
1995656 - CVE-2021-36221 golang: net/http/httputil: panic due to racy read of persistConn after handler panic 2016256 - Release of OpenShift Serverless Eventing 1.19.0 2016258 - Release of OpenShift Serverless Serving 1.19.0
-
7) - noarch, x86_64
-
8) - aarch64, noarch, ppc64le, s390x, x86_64
-
The python27 packages provide a stable release of Python 2.7 with a number of additional utilities and database connectors for MySQL and PostgreSQL
{ "@context": { "@vocab": "https://www.variotdbs.pl/ref/VARIoTentry#", "affected_products": { "@id": "https://www.variotdbs.pl/ref/affected_products" }, "configurations": { "@id": "https://www.variotdbs.pl/ref/configurations" }, "credits": { "@id": "https://www.variotdbs.pl/ref/credits" }, "cvss": { "@id": "https://www.variotdbs.pl/ref/cvss/" }, "description": { "@id": "https://www.variotdbs.pl/ref/description/" }, "exploit_availability": { "@id": "https://www.variotdbs.pl/ref/exploit_availability/" }, "external_ids": { "@id": "https://www.variotdbs.pl/ref/external_ids/" }, "iot": { "@id": "https://www.variotdbs.pl/ref/iot/" }, "iot_taxonomy": { "@id": "https://www.variotdbs.pl/ref/iot_taxonomy/" }, "patch": { "@id": "https://www.variotdbs.pl/ref/patch/" }, "problemtype_data": { "@id": "https://www.variotdbs.pl/ref/problemtype_data/" }, "references": { "@id": "https://www.variotdbs.pl/ref/references/" }, "sources": { "@id": "https://www.variotdbs.pl/ref/sources/" }, "sources_release_date": { "@id": "https://www.variotdbs.pl/ref/sources_release_date/" }, "sources_update_date": { "@id": "https://www.variotdbs.pl/ref/sources_update_date/" }, "threat_type": { "@id": "https://www.variotdbs.pl/ref/threat_type/" }, "title": { "@id": "https://www.variotdbs.pl/ref/title/" }, "type": { "@id": "https://www.variotdbs.pl/ref/type/" } }, "@id": "https://www.variotdbs.pl/vuln/VAR-202109-1966", "affected_products": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/affected_products#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" }, "@id": "https://www.variotdbs.pl/ref/sources" } }, "data": [ { "model": "fedora", "scope": "eq", "trust": 1.0, "vendor": "fedoraproject", "version": "34" }, { "model": "ontap select deploy administration utility", "scope": "eq", "trust": 1.0, "vendor": "netapp", "version": null }, { "model": "python", "scope": "lt", "trust": 1.0, "vendor": "python", "version": "3.7.11" }, { "model": "enterprise linux for power little endian", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.0" }, { "model": "enterprise linux", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.0" }, { "model": "enterprise linux server tus", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.4" }, { "model": "python", "scope": "gte", "trust": 1.0, "vendor": "python", "version": "3.8.0" }, { "model": "solidfire\\, enterprise sds \\\u0026 hci storage node", "scope": "eq", "trust": 1.0, "vendor": "netapp", "version": null }, { "model": "python", "scope": "lt", "trust": 1.0, "vendor": "python", "version": "3.6.14" }, { "model": "codeready linux builder", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.0" }, { "model": "fedora", "scope": "eq", "trust": 1.0, "vendor": "fedoraproject", "version": "36" }, { "model": "enterprise linux server update services for sap solutions", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.4" }, { "model": "enterprise linux for power little endian eus", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.4" }, { "model": "extra packages for enterprise linux", "scope": "eq", "trust": 1.0, "vendor": "fedoraproject", "version": "7.0" }, { "model": "hci compute node", "scope": "eq", "trust": 1.0, "vendor": "netapp", "version": null }, { "model": "management services for element software and netapp hci", "scope": "eq", "trust": 1.0, "vendor": "netapp", "version": null }, { "model": "codeready linux builder for power little endian", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.0" }, { "model": "enterprise linux eus", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.4" }, { "model": "enterprise linux server aus", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.4" }, { "model": "enterprise linux server for power little endian update services for sap solutions", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.4" }, { "model": "fedora", "scope": "eq", "trust": 1.0, "vendor": "fedoraproject", "version": "33" }, { "model": "python", "scope": "eq", "trust": 1.0, "vendor": "python", "version": "3.10.0" }, { "model": "enterprise linux for ibm z systems", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.0" }, { "model": "python", "scope": "lt", "trust": 1.0, "vendor": "python", "version": "3.9.5" }, { "model": "python", "scope": "gte", "trust": 1.0, "vendor": "python", "version": "3.9.0" }, { "model": "python", "scope": "gte", "trust": 1.0, "vendor": "python", "version": "3.7.0" }, { "model": "python", "scope": "lt", "trust": 1.0, "vendor": "python", "version": "3.8.10" }, { "model": "fedora", "scope": "eq", "trust": 1.0, "vendor": "fedoraproject", "version": "35" }, { "model": "codeready linux builder for ibm z systems", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.0" }, { "model": "enterprise linux for ibm z systems eus", "scope": "eq", "trust": 1.0, "vendor": "redhat", "version": "8.4" }, { "model": "red hat enterprise linux for ibm z systems", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "fedora", "scope": null, "trust": 0.8, "vendor": "fedora", "version": null }, { "model": "red hat enterprise linux for power, little endian - update services for sap solutions", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "red hat enterprise linux server aus", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "red hat enterprise linux for ibm z systems - extended update support", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "solidfire enterprise sds \u0026 hci storage node", "scope": null, "trust": 0.8, "vendor": "netapp", "version": null }, { "model": "red hat enterprise linux server tus", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "red hat enterprise linux", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "ontap select deploy administration utility", "scope": null, "trust": 0.8, "vendor": "netapp", "version": null }, { "model": "python", "scope": null, "trust": 0.8, "vendor": "python", "version": null }, { "model": "hci compute node", "scope": null, "trust": 0.8, "vendor": "netapp", "version": null }, { "model": "red hat enterprise linux for power, little endian - extended update support", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "red hat enterprise linux eus", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "red hat enterprise linux server update services for sap solutions", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "management software for element software and netapp hci", "scope": null, "trust": 0.8, "vendor": "netapp", "version": null }, { "model": "codeready linux builder for power little endian", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "codeready linux builder for ibm z systems", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "codeready linux builder", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null }, { "model": "extra packages for enterprise linux", "scope": null, "trust": 0.8, "vendor": "fedora", "version": null }, { "model": "red hat enterprise linux for power, little endian", "scope": null, "trust": 0.8, "vendor": "\u30ec\u30c3\u30c9\u30cf\u30c3\u30c8", "version": null } ], "sources": [ { "db": "JVNDB", "id": "JVNDB-2021-018724" }, { "db": "NVD", "id": "CVE-2021-3733" } ] }, "credits": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/credits#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "Red Hat", "sources": [ { "db": "PACKETSTORM", "id": "165631" }, { "db": "PACKETSTORM", "id": "165135" }, { "db": "PACKETSTORM", "id": "165099" }, { "db": "PACKETSTORM", "id": "164741" }, { "db": "PACKETSTORM", "id": "165053" }, { "db": "PACKETSTORM", "id": "166913" }, { "db": "PACKETSTORM", "id": "167043" } ], "trust": 0.7 }, "cve": "CVE-2021-3733", "cvss": { "@context": { "cvssV2": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/cvss/cvssV2#" }, "@id": "https://www.variotdbs.pl/ref/cvss/cvssV2" }, "cvssV3": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/cvss/cvssV3#" }, "@id": "https://www.variotdbs.pl/ref/cvss/cvssV3/" }, "severity": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/cvss/severity#" }, "@id": "https://www.variotdbs.pl/ref/cvss/severity" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" }, "@id": "https://www.variotdbs.pl/ref/sources" } }, "data": [ { "cvssV2": [ { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "SINGLE", "author": "nvd@nist.gov", "availabilityImpact": "PARTIAL", "baseScore": 4.0, "confidentialityImpact": "NONE", "exploitabilityScore": 8.0, "id": "CVE-2021-3733", "impactScore": 2.9, "integrityImpact": "NONE", "severity": "MEDIUM", "trust": 1.8, "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P", "version": "2.0" }, { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "SINGLE", "author": "VULHUB", "availabilityImpact": "PARTIAL", "baseScore": 4.0, "confidentialityImpact": "NONE", "exploitabilityScore": 8.0, "id": "VHN-397442", "impactScore": 2.9, "integrityImpact": "NONE", "severity": "MEDIUM", "trust": 0.1, "vectorString": "AV:N/AC:L/AU:S/C:N/I:N/A:P", "version": "2.0" } ], "cvssV3": [ { "attackComplexity": "LOW", "attackVector": "NETWORK", "author": "nvd@nist.gov", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "exploitabilityScore": 2.8, "id": "CVE-2021-3733", "impactScore": 3.6, "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "trust": 1.0, "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, { "attackComplexity": "Low", "attackVector": "Network", "author": "NVD", "availabilityImpact": "High", "baseScore": 6.5, "baseSeverity": "Medium", "confidentialityImpact": "None", "exploitabilityScore": null, "id": "CVE-2021-3733", "impactScore": null, "integrityImpact": "None", "privilegesRequired": "Low", "scope": "Unchanged", "trust": 0.8, "userInteraction": "None", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.0" } ], "severity": [ { "author": "nvd@nist.gov", "id": "CVE-2021-3733", "trust": 1.0, "value": "MEDIUM" }, { "author": "NVD", "id": "CVE-2021-3733", "trust": 0.8, "value": "Medium" }, { "author": "VULHUB", "id": "VHN-397442", "trust": 0.1, "value": "MEDIUM" } ] } ], "sources": [ { "db": "VULHUB", "id": "VHN-397442" }, { "db": "JVNDB", "id": "JVNDB-2021-018724" }, { "db": "NVD", "id": "CVE-2021-3733" } ] }, "description": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/description#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "There\u0027s a flaw in urllib\u0027s AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability. Python Software Foundation of Python Products from other vendors have resource exhaustion vulnerabilities.Service operation interruption (DoS) It may be in a state. Python is an open source, object-oriented programming language developed by the Python Foundation. The language is scalable, supports modules and packages, and supports multiple platforms. A code issue vulnerability exists in Python due to a failure in the product to properly handle RCFS. An attacker could exploit this vulnerability to cause a denial of service. The following products and versions are affected: python3.5 For Ubuntu 16.04 ESM. ==========================================================================\nUbuntu Security Notice USN-5200-1\nDecember 17, 2021\n\npython3.7, python3.8 vulnerabilities\n==========================================================================\n\nA security issue affects these releases of Ubuntu and its derivatives:\n\n- Ubuntu 18.04 LTS\n\nSummary:\n\nPython could be made to crash if it receives specially crafted input \nfrom a malicious server. \n(CVE-2020-8492)\n\nIt was discovered that the urllib.request.AbstractBasicAuthHandler class\nin Python contains regex with a quadratic worst-case time complexity. \n(CVE-2021-3737)\n\nUpdate instructions:\n\nThe problem can be corrected by updating your system to the following\npackage versions:\n\nUbuntu 18.04 LTS:\n libpython3.7-stdlib 3.7.5-2ubuntu1~18.04.2\n libpython3.8-stdlib 3.8.0-3ubuntu1~18.04.2\n python3.7 3.7.5-2ubuntu1~18.04.2\n python3.7-minimal 3.7.5-2ubuntu1~18.04.2\n python3.8 3.8.0-3ubuntu1~18.04.2\n python3.8-minimal 3.8.0-3ubuntu1~18.04.2\n\nIn general, a standard system update will make all the necessary changes. Bugs fixed (https://bugzilla.redhat.com/):\n\n1983596 - CVE-2021-34558 golang: crypto/tls: certificate of wrong type is causing TLS client to panic\n1992006 - CVE-2021-29923 golang: net: incorrect parsing of extraneous zero characters at the beginning of an IP address octet\n1997017 - unprivileged client fails to get guest agent data\n1998855 - Node drain: Sometimes source virt-launcher pod status is Failed and not Completed\n2000251 - RoleBinding and ClusterRoleBinding brought in by kubevirt does not get reconciled when kind is ServiceAccount\n2001270 - [VMIO] [Warm from Vmware] Snapshot files are not deleted after Successful Import\n2001281 - [VMIO] [Warm from VMware] Source VM should not be turned ON if vmio import is removed\n2001901 - [4.8.3] NNCP creation failures after nmstate-handler pod deletion\n2007336 - 4.8.3 containers\n2007776 - Failed to Migrate Windows VM with CDROM (readonly)\n2008511 - [CNV-4.8.3] VMI is in LiveMigrate loop when Upgrading Cluster from 2.6.7/4.7.32 to OCP 4.8.13\n2012890 - With descheduler during multiple VMIs migrations, some VMs are restarted\n2025475 - [4.8.3] Upgrade from 2.6 to 4.x versions failed due to vlan-filtering issues\n2026881 - [4.8.3] vlan-filtering is getting applied on veth ports\n\n5. Summary:\n\nThe Migration Toolkit for Containers (MTC) 1.5.2 is now available. Description:\n\nThe Migration Toolkit for Containers (MTC) enables you to migrate\nKubernetes resources, persistent volume data, and internal container images\nbetween OpenShift Container Platform clusters, using the MTC web console or\nthe Kubernetes API. Bugs fixed (https://bugzilla.redhat.com/):\n\n2000734 - CVE-2021-3757 nodejs-immer: prototype pollution may lead to DoS or remote code execution\n2005438 - Combining Rsync and Stunnel in a single pod can degrade performance (1.5 backport)\n2006842 - MigCluster CR remains in \"unready\" state and source registry is inaccessible after temporary shutdown of source cluster\n2007429 - \"oc describe\" and \"oc log\" commands on \"Migration resources\" tree cannot be copied after failed migration\n2022017 - CVE-2021-3948 mig-controller: incorrect namespaces handling may lead to not authorized usage of Migration Toolkit for Containers (MTC)\n\n5. -----BEGIN PGP SIGNED MESSAGE-----\nHash: SHA256\n\n=====================================================================\n Red Hat Security Advisory\n\nSynopsis: Moderate: python3 security update\nAdvisory ID: RHSA-2021:4057-01\nProduct: Red Hat Enterprise Linux\nAdvisory URL: https://access.redhat.com/errata/RHSA-2021:4057\nIssue date: 2021-11-02\nCVE Names: CVE-2021-3733 \n=====================================================================\n\n1. Summary:\n\nAn update for python3 is now available for Red Hat Enterprise Linux 8. \n\nRed Hat Product Security has rated this update as having a security impact\nof Moderate. A Common Vulnerability Scoring System (CVSS) base score, which\ngives a detailed severity rating, is available for each vulnerability from\nthe CVE link(s) in the References section. \n\n2. Relevant releases/architectures:\n\nRed Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64\nRed Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64\n\n3. Description:\n\nPython is an interpreted, interactive, object-oriented programming\nlanguage, which includes modules, classes, exceptions, very high level\ndynamic data types and dynamic typing. Python supports interfaces to many\nsystem calls and libraries, as well as to various windowing systems. \n\nSecurity Fix(es):\n\n* python: urllib: Regular expression DoS in AbstractBasicAuthHandler\n(CVE-2021-3733)\n\nFor more details about the security issue(s), including the impact, a CVSS\nscore, acknowledgments, and other related information, refer to the CVE\npage(s) listed in the References section. \n\n4. Solution:\n\nFor details on how to apply this update, which includes the changes\ndescribed in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258\n\n5. Bugs fixed (https://bugzilla.redhat.com/):\n\n1995234 - CVE-2021-3733 python: urllib: Regular expression DoS in AbstractBasicAuthHandler\n\n6. Package List:\n\nRed Hat Enterprise Linux AppStream (v. 8):\n\naarch64:\nplatform-python-debug-3.6.8-39.el8_4.aarch64.rpm\nplatform-python-devel-3.6.8-39.el8_4.aarch64.rpm\npython3-debuginfo-3.6.8-39.el8_4.aarch64.rpm\npython3-debugsource-3.6.8-39.el8_4.aarch64.rpm\npython3-idle-3.6.8-39.el8_4.aarch64.rpm\npython3-tkinter-3.6.8-39.el8_4.aarch64.rpm\n\nppc64le:\nplatform-python-debug-3.6.8-39.el8_4.ppc64le.rpm\nplatform-python-devel-3.6.8-39.el8_4.ppc64le.rpm\npython3-debuginfo-3.6.8-39.el8_4.ppc64le.rpm\npython3-debugsource-3.6.8-39.el8_4.ppc64le.rpm\npython3-idle-3.6.8-39.el8_4.ppc64le.rpm\npython3-tkinter-3.6.8-39.el8_4.ppc64le.rpm\n\ns390x:\nplatform-python-debug-3.6.8-39.el8_4.s390x.rpm\nplatform-python-devel-3.6.8-39.el8_4.s390x.rpm\npython3-debuginfo-3.6.8-39.el8_4.s390x.rpm\npython3-debugsource-3.6.8-39.el8_4.s390x.rpm\npython3-idle-3.6.8-39.el8_4.s390x.rpm\npython3-tkinter-3.6.8-39.el8_4.s390x.rpm\n\nx86_64:\nplatform-python-3.6.8-39.el8_4.i686.rpm\nplatform-python-debug-3.6.8-39.el8_4.i686.rpm\nplatform-python-debug-3.6.8-39.el8_4.x86_64.rpm\nplatform-python-devel-3.6.8-39.el8_4.i686.rpm\nplatform-python-devel-3.6.8-39.el8_4.x86_64.rpm\npython3-debuginfo-3.6.8-39.el8_4.i686.rpm\npython3-debuginfo-3.6.8-39.el8_4.x86_64.rpm\npython3-debugsource-3.6.8-39.el8_4.i686.rpm\npython3-debugsource-3.6.8-39.el8_4.x86_64.rpm\npython3-idle-3.6.8-39.el8_4.i686.rpm\npython3-idle-3.6.8-39.el8_4.x86_64.rpm\npython3-test-3.6.8-39.el8_4.i686.rpm\npython3-tkinter-3.6.8-39.el8_4.i686.rpm\npython3-tkinter-3.6.8-39.el8_4.x86_64.rpm\n\nRed Hat Enterprise Linux BaseOS (v. 8):\n\nSource:\npython3-3.6.8-39.el8_4.src.rpm\n\naarch64:\nplatform-python-3.6.8-39.el8_4.aarch64.rpm\npython3-debuginfo-3.6.8-39.el8_4.aarch64.rpm\npython3-debugsource-3.6.8-39.el8_4.aarch64.rpm\npython3-libs-3.6.8-39.el8_4.aarch64.rpm\npython3-test-3.6.8-39.el8_4.aarch64.rpm\n\nppc64le:\nplatform-python-3.6.8-39.el8_4.ppc64le.rpm\npython3-debuginfo-3.6.8-39.el8_4.ppc64le.rpm\npython3-debugsource-3.6.8-39.el8_4.ppc64le.rpm\npython3-libs-3.6.8-39.el8_4.ppc64le.rpm\npython3-test-3.6.8-39.el8_4.ppc64le.rpm\n\ns390x:\nplatform-python-3.6.8-39.el8_4.s390x.rpm\npython3-debuginfo-3.6.8-39.el8_4.s390x.rpm\npython3-debugsource-3.6.8-39.el8_4.s390x.rpm\npython3-libs-3.6.8-39.el8_4.s390x.rpm\npython3-test-3.6.8-39.el8_4.s390x.rpm\n\nx86_64:\nplatform-python-3.6.8-39.el8_4.x86_64.rpm\npython3-debuginfo-3.6.8-39.el8_4.i686.rpm\npython3-debuginfo-3.6.8-39.el8_4.x86_64.rpm\npython3-debugsource-3.6.8-39.el8_4.i686.rpm\npython3-debugsource-3.6.8-39.el8_4.x86_64.rpm\npython3-libs-3.6.8-39.el8_4.i686.rpm\npython3-libs-3.6.8-39.el8_4.x86_64.rpm\npython3-test-3.6.8-39.el8_4.x86_64.rpm\n\nThese packages are GPG signed by Red Hat for security. Our key and\ndetails on how to verify the signature are available from\nhttps://access.redhat.com/security/team/key/\n\n7. References:\n\nhttps://access.redhat.com/security/cve/CVE-2021-3733\nhttps://access.redhat.com/security/updates/classification/#moderate\n\n8. Contact:\n\nThe Red Hat security contact is \u003csecalert@redhat.com\u003e. More contact\ndetails at https://access.redhat.com/security/team/contact/\n\nCopyright 2021 Red Hat, Inc. \n-----BEGIN PGP SIGNATURE-----\nVersion: GnuPG v1\n\niQIVAwUBYYD6u9zjgjWX9erEAQgCbg//S3byb5BXGosk0v+LDiREjmiOkmk9QpLJ\n8SCgT7ap9IRI6rghoGv7bsLpRyydrd8KR0pIDCQOJngEGZfJEUiwk6QhdFs0JHqG\naHb1JJCBGTyQ9b0jhrKlJKCvJJk9oscRhkVn2AYm9r4fAnwzSqLaTd+8/PxJrKi+\n7M6I3xh3MYVj5j8Y56GCXYbuAxQqNRPUunzLC8tr79zuVt1iH5qAbff/Dmtkpl4A\nzDDMp42s7UN1H+Y4pRo9b7MqJLpa1GjuZWsVr53QZu4al7Cbw+iAlz4R2P3pQVKv\nuHCkl7pWi+v22po5C55+djkPPzzu0NiVJ9CLI/gtI4lx7dJ6uKqNaPvetzuaKaR5\n9HEFIRat1V/jD/boAa4gUscosId8h8Arm8UDLaIoJ5IqdNYrRb+AtXpBN2Clg0S2\nz9KLbG7jNFAH4sqmIsYz2t+O8pQteMzQdbhoSx8KdaQgIqjUBd+dBXE3P0kndc0g\n1No7qsDjavlD31uvXC6K+RO0bESW7kZbcscseO5xiiMNBCbWjKVjKo5DavNxmrTf\nW4DkMsSzmijKqBsoBgxizFiCF82NH+UXIY/PSNJ4h8KKwi377FRwVvjg8JC5TBPG\nWpg6oNbHBTrWEmdlOcL6C13gjIDVtU3lWVomlGYkb7/t4KtjiorJuzuolcqpkRVp\nYfBN+OdHhpA=\n=MOG7\n-----END PGP SIGNATURE-----\n\n--\nRHSA-announce mailing list\nRHSA-announce@redhat.com\nhttps://listman.redhat.com/mailman/listinfo/rhsa-announce\n. \nThis version of the OpenShift Serverless Operator is supported on Red Hat\nOpenShift Container Platform versions 4.6, 4.7, 4.8 and 4.9, and includes\nsecurity and bug fixes and enhancements. Bugs fixed (https://bugzilla.redhat.com/):\n\n1995656 - CVE-2021-36221 golang: net/http/httputil: panic due to racy read of persistConn after handler panic\n2016256 - Release of OpenShift Serverless Eventing 1.19.0\n2016258 - Release of OpenShift Serverless Serving 1.19.0\n\n5. 7) - noarch, x86_64\n\n3. 8) - aarch64, noarch, ppc64le, s390x, x86_64\n\n3. The python27 packages provide a stable release of\nPython 2.7 with a number of additional utilities and database connectors\nfor MySQL and PostgreSQL", "sources": [ { "db": "NVD", "id": "CVE-2021-3733" }, { "db": "JVNDB", "id": "JVNDB-2021-018724" }, { "db": "VULHUB", "id": "VHN-397442" }, { "db": "PACKETSTORM", "id": "165631" }, { "db": "PACKETSTORM", "id": "165361" }, { "db": "PACKETSTORM", "id": "165363" }, { "db": "PACKETSTORM", "id": "165135" }, { "db": "PACKETSTORM", "id": "165099" }, { "db": "PACKETSTORM", "id": "164741" }, { "db": "PACKETSTORM", "id": "165053" }, { "db": "PACKETSTORM", "id": "166913" }, { "db": "PACKETSTORM", "id": "167043" } ], "trust": 2.52 }, "external_ids": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/external_ids#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "db": "NVD", "id": "CVE-2021-3733", "trust": 3.6 }, { "db": "JVNDB", "id": "JVNDB-2021-018724", "trust": 0.8 }, { "db": "PACKETSTORM", "id": "165053", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "167043", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "165363", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "164741", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "165361", "trust": 0.2 }, { "db": "PACKETSTORM", "id": "165008", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "164948", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "165337", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "167023", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "164859", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "164993", "trust": 0.1 }, { "db": "CNNVD", "id": "CNNVD-202109-1139", "trust": 0.1 }, { "db": "VULHUB", "id": "VHN-397442", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "165631", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "165135", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "165099", "trust": 0.1 }, { "db": "PACKETSTORM", "id": "166913", "trust": 0.1 } ], "sources": [ { "db": "VULHUB", "id": "VHN-397442" }, { "db": "JVNDB", "id": "JVNDB-2021-018724" }, { "db": "PACKETSTORM", "id": "165631" }, { "db": "PACKETSTORM", "id": "165361" }, { "db": "PACKETSTORM", "id": "165363" }, { "db": "PACKETSTORM", "id": "165135" }, { "db": "PACKETSTORM", "id": "165099" }, { "db": "PACKETSTORM", "id": "164741" }, { "db": "PACKETSTORM", "id": "165053" }, { "db": "PACKETSTORM", "id": "166913" }, { "db": "PACKETSTORM", "id": "167043" }, { "db": "NVD", "id": "CVE-2021-3733" } ] }, "id": "VAR-202109-1966", "iot": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/iot#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": true, "sources": [ { "db": "VULHUB", "id": "VHN-397442" } ], "trust": 0.01 }, "last_update_date": "2024-09-19T20:36:57.529000Z", "problemtype_data": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/problemtype_data#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "problemtype": "CWE-400", "trust": 1.1 }, { "problemtype": "Resource exhaustion (CWE-400) [NVD evaluation ]", "trust": 0.8 } ], "sources": [ { "db": "VULHUB", "id": "VHN-397442" }, { "db": "JVNDB", "id": "JVNDB-2021-018724" }, { "db": "NVD", "id": "CVE-2021-3733" } ] }, "references": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/references#", "data": { "@container": "@list" }, "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": [ { "trust": 1.9, "url": "https://security.netapp.com/advisory/ntap-20220407-0001/" }, { "trust": 1.9, "url": "https://bugs.python.org/issue43075" }, { "trust": 1.9, "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1995234" }, { "trust": 1.9, "url": "https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb" }, { "trust": 1.9, "url": "https://github.com/python/cpython/pull/24391" }, { "trust": 1.9, "url": "https://ubuntu.com/security/cve-2021-3733" }, { "trust": 1.8, "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html" }, { "trust": 1.8, "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html" }, { "trust": 1.4, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-3733" }, { "trust": 0.7, "url": "https://access.redhat.com/security/cve/cve-2021-3733" }, { "trust": 0.7, "url": "https://listman.redhat.com/mailman/listinfo/rhsa-announce" }, { "trust": 0.7, "url": "https://bugzilla.redhat.com/):" }, { "trust": 0.7, "url": "https://access.redhat.com/security/team/contact/" }, { "trust": 0.7, "url": "https://access.redhat.com/security/updates/classification/#moderate" }, { "trust": 0.4, "url": "https://access.redhat.com/security/cve/cve-2021-33938" }, { "trust": 0.4, "url": "https://access.redhat.com/security/cve/cve-2021-33929" }, { "trust": 0.4, "url": "https://access.redhat.com/security/cve/cve-2021-33928" }, { "trust": 0.4, "url": "https://access.redhat.com/security/cve/cve-2021-22946" }, { "trust": 0.4, "url": "https://access.redhat.com/security/cve/cve-2021-33930" }, { "trust": 0.4, "url": "https://access.redhat.com/security/cve/cve-2021-22947" }, { "trust": 0.4, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-3737" }, { "trust": 0.4, "url": "https://access.redhat.com/articles/11258" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-16135" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-3200" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-37750" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-5827" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-27645" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-33574" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2020-13435" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2019-5827" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2020-24370" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2019-13751" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2019-19603" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-35942" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2019-17594" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2020-12762" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-36086" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-3778" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-13750" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-13751" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-22898" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-12762" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2020-16135" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-36084" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-3800" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-17594" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-36087" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-3445" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-13435" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-19603" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-22925" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-18218" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-20232" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-20266" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2019-20838" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-22876" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-20231" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2020-14155" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-20838" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-36085" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-33560" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2019-17595" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-14155" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-28153" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2019-13750" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2019-18218" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-3580" }, { "trust": 0.3, "url": "https://access.redhat.com/security/cve/cve-2021-3796" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-17595" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-22946" }, { "trust": 0.3, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-22947" }, { "trust": 0.3, "url": "https://access.redhat.com/security/team/key/" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2020-14145" }, { "trust": 0.2, "url": "https://docs.openshift.com/container-platform/latest/migration_toolkit_for_containers/installing-mtc.html" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-14145" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2021-3572" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2021-3948" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2021-42574" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2021-3426" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-22876" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2021-23841" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-20231" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-24370" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-22925" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2021-23840" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-22898" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-20673" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-20266" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2018-20673" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2021-36222" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-20232" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2021-3737" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2022-0391" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2022-0391" }, { "trust": 0.2, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-4189" }, { "trust": 0.2, "url": "https://access.redhat.com/security/cve/cve-2021-4189" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-25013" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-25012" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-27823" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-35522" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-1870" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-35524" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-3575" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30758" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-25013" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-13558" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-15389" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-25009" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-5727" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-43527" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-5785" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-41617" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30665" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2019-12973" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30689" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-20847" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30682" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-10001" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-25014" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-25012" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-35521" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-18032" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-1801" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-1765" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2016-4658" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-20845" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-26927" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-20847" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-17541" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-27918" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-36331" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-3712" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30749" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30795" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-5785" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-1788" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-31535" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-5727" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30744" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-21775" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-21806" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-27814" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-36330" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-36241" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30797" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2016-4658" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-13558" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-20321" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-27842" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-36332" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-1799" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-25010" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-21779" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-10001" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-29623" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-20271" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-25014" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-27828" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2019-12973" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2018-20845" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-1844" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-3481" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-25009" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-1871" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2018-25010" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-29338" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30734" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-35523" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-26926" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30720" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-28650" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-27843" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-24870" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-27845" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-1789" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30663" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-30799" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-3272" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2022:0202" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-15389" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-27824" }, { "trust": 0.1, "url": "https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-8492" }, { "trust": 0.1, "url": "https://ubuntu.com/security/notices/usn-5200-1" }, { "trust": 0.1, "url": "https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2" }, { "trust": 0.1, "url": "https://ubuntu.com/security/notices/usn-5199-1" }, { "trust": 0.1, "url": "https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-25648" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2020-36385" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-34558" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-43267" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-0512" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-29923" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-0512" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-36385" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-20317" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-20317" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2021:4914" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2020-25648" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-3656" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-28950" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-27218" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-3757" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2021:4848" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-23841" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-27218" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-3620" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-23840" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2021:4057" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-33929" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-33930" }, { "trust": 0.1, "url": "https://access.redhat.com/documentation/en-us/openshift_container_platform/4.7/html/serverless/index" }, { "trust": 0.1, "url": "https://access.redhat.com/documentation/en-us/openshift_container_platform/4.8/html/serverless/index" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2021:4766" }, { "trust": 0.1, "url": "https://access.redhat.com/documentation/en-us/openshift_container_platform/4.6/html/serverless/index" }, { "trust": 0.1, "url": "https://access.redhat.com/documentation/en-us/openshift_container_platform/4.9/html/serverless/index" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-36221" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-36221" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-33928" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-33938" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2022:1663" }, { "trust": 0.1, "url": "https://access.redhat.com/security/cve/cve-2021-43818" }, { "trust": 0.1, "url": "https://access.redhat.com/errata/rhsa-2022:1821" }, { "trust": 0.1, "url": "https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.6_release_notes/" }, { "trust": 0.1, "url": "https://nvd.nist.gov/vuln/detail/cve-2021-43818" } ], "sources": [ { "db": "VULHUB", "id": "VHN-397442" }, { "db": "JVNDB", "id": "JVNDB-2021-018724" }, { "db": "PACKETSTORM", "id": "165631" }, { "db": "PACKETSTORM", "id": "165361" }, { "db": "PACKETSTORM", "id": "165363" }, { "db": "PACKETSTORM", "id": "165135" }, { "db": "PACKETSTORM", "id": "165099" }, { "db": "PACKETSTORM", "id": "164741" }, { "db": "PACKETSTORM", "id": "165053" }, { "db": "PACKETSTORM", "id": "166913" }, { "db": "PACKETSTORM", "id": "167043" }, { "db": "NVD", "id": "CVE-2021-3733" } ] }, "sources": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#", "data": { "@container": "@list" } }, "data": [ { "db": "VULHUB", "id": "VHN-397442" }, { "db": "JVNDB", "id": "JVNDB-2021-018724" }, { "db": "PACKETSTORM", "id": "165631" }, { "db": "PACKETSTORM", "id": "165361" }, { "db": "PACKETSTORM", "id": "165363" }, { "db": "PACKETSTORM", "id": "165135" }, { "db": "PACKETSTORM", "id": "165099" }, { "db": "PACKETSTORM", "id": "164741" }, { "db": "PACKETSTORM", "id": "165053" }, { "db": "PACKETSTORM", "id": "166913" }, { "db": "PACKETSTORM", "id": "167043" }, { "db": "NVD", "id": "CVE-2021-3733" } ] }, "sources_release_date": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources_release_date#", "data": { "@container": "@list" } }, "data": [ { "date": "2022-03-10T00:00:00", "db": "VULHUB", "id": "VHN-397442" }, { "date": "2023-07-05T00:00:00", "db": "JVNDB", "id": "JVNDB-2021-018724" }, { "date": "2022-01-20T17:48:29", "db": "PACKETSTORM", "id": "165631" }, { "date": "2021-12-17T19:23:35", "db": "PACKETSTORM", "id": "165361" }, { "date": "2021-12-17T19:23:51", "db": "PACKETSTORM", "id": "165363" }, { "date": "2021-12-03T16:41:45", "db": "PACKETSTORM", "id": "165135" }, { "date": "2021-11-30T14:44:48", "db": "PACKETSTORM", "id": "165099" }, { "date": "2021-11-02T15:33:39", "db": "PACKETSTORM", "id": "164741" }, { "date": "2021-11-23T17:10:05", "db": "PACKETSTORM", "id": "165053" }, { "date": "2022-05-02T15:26:53", "db": "PACKETSTORM", "id": "166913" }, { "date": "2022-05-11T15:59:26", "db": "PACKETSTORM", "id": "167043" }, { "date": "2022-03-10T17:42:59.623000", "db": "NVD", "id": "CVE-2021-3733" } ] }, "sources_update_date": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources_update_date#", "data": { "@container": "@list" } }, "data": [ { "date": "2022-10-26T00:00:00", "db": "VULHUB", "id": "VHN-397442" }, { "date": "2023-07-05T08:12:00", "db": "JVNDB", "id": "JVNDB-2021-018724" }, { "date": "2023-06-30T23:15:09.690000", "db": "NVD", "id": "CVE-2021-3733" } ] }, "title": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/title#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "Python\u00a0Software\u00a0Foundation\u00a0 of \u00a0Python\u00a0 Vulnerability related to resource exhaustion in products of multiple vendors", "sources": [ { "db": "JVNDB", "id": "JVNDB-2021-018724" } ], "trust": 0.8 }, "type": { "@context": { "@vocab": "https://www.variotdbs.pl/ref/type#", "sources": { "@container": "@list", "@context": { "@vocab": "https://www.variotdbs.pl/ref/sources#" } } }, "data": "code execution", "sources": [ { "db": "PACKETSTORM", "id": "165099" } ], "trust": 0.1 } }
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.