Path traversal in Babel - CVE-2021-20095
Published: May 10, 2021
Vulnerability identifier: #VU53015
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20095
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can load arbitrary files on disk and execute arbitrary code.
Affected software
Babel
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Ansible Automation Platform
python-babel-localedata (Ubuntu package)
python-babel (Ubuntu package)
python3-babel (Ubuntu package)
babel (Red Hat package)
python3-babel
babel
python2-babel
babel-help
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Ansible Automation Platform
python-babel-localedata (Ubuntu package)
python-babel (Ubuntu package)
python3-babel (Ubuntu package)
babel (Red Hat package)
python3-babel
babel
python2-babel
babel-help
How to mitigate CVE-2021-20095
Install update from vendor's website.
Babel - update to 2.9.1
Migration Toolkit for Containers - update to 1.7.4
python-babel-localedata (Ubuntu package) - addressed in versions 2.4.0+dfsg.1-2ubuntu1.1, 2.6.0+dfsg.1-1ubuntu2.2, 2.8.0+dfsg.1-4ubuntu0.1, 2.8.0+dfsg.1-6ubuntu0.1
python-babel (Ubuntu package) - addressed in versions 2.4.0+dfsg.1-2ubuntu1.1, 2.6.0+dfsg.1-1ubuntu2.2
python3-babel (Ubuntu package) - addressed in versions 2.4.0+dfsg.1-2ubuntu1.1, 2.6.0+dfsg.1-1ubuntu2.2, 2.8.0+dfsg.1-4ubuntu0.1, 2.8.0+dfsg.1-6ubuntu0.1
babel (Red Hat package) - update to 2.5.1-7.el8
python3-babel - update to 2.8.0-3
babel - update to 2.8.0-3
python2-babel - update to 2.8.0-3
babel-help - update to 2.8.0-3
babel - addressed in versions 2.8.0-4.fc32, 2.8.1-2.fc33
Red Hat OpenShift Container Platform - update to 4.11.0
Migration Toolkit for Containers - update to 1.7.4
python-babel-localedata (Ubuntu package) - addressed in versions 2.4.0+dfsg.1-2ubuntu1.1, 2.6.0+dfsg.1-1ubuntu2.2, 2.8.0+dfsg.1-4ubuntu0.1, 2.8.0+dfsg.1-6ubuntu0.1
python-babel (Ubuntu package) - addressed in versions 2.4.0+dfsg.1-2ubuntu1.1, 2.6.0+dfsg.1-1ubuntu2.2
python3-babel (Ubuntu package) - addressed in versions 2.4.0+dfsg.1-2ubuntu1.1, 2.6.0+dfsg.1-1ubuntu2.2, 2.8.0+dfsg.1-4ubuntu0.1, 2.8.0+dfsg.1-6ubuntu0.1
babel (Red Hat package) - update to 2.5.1-7.el8
python3-babel - update to 2.8.0-3
babel - update to 2.8.0-3
python2-babel - update to 2.8.0-3
babel-help - update to 2.8.0-3
babel - addressed in versions 2.8.0-4.fc32, 2.8.1-2.fc33
Red Hat OpenShift Container Platform - update to 4.11.0
External References
- https://www.tenable.com/security/research/tra-2021-14
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKXUEWVKU5WASYSAFXQP6SFSDOG773RV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MORYINYUSYI6XLC4UKPRGGFD2WMO7GSM/
Related Security Bulletins
- Path traversal in Babel
- Arch Linux update for python-babel
- Ubuntu update for python-babel
- Gentoo update for Babel
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Red Hat Enterprise Linux 8 update for babel
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- openEuler 20.03 LTS SP1 update for babel
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- Red Hat Enterprise Linux 8 update for the python38:3.8 and python38-devel:3.8 modules
- Fedora 33 update for babel
- Fedora 32 update for babel