Path traversal in Babel - CVE-2021-20095

 

Path traversal in Babel - CVE-2021-20095

Published: May 10, 2021


Vulnerability identifier: #VU53015
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-20095
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can load arbitrary files on disk and execute arbitrary code.


Affected software

Babel
Arch Linux
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
openEuler
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Ansible Automation Platform
python-babel-localedata (Ubuntu package)
python-babel (Ubuntu package)
python3-babel (Ubuntu package)
babel (Red Hat package)
python3-babel
babel
python2-babel
babel-help

How to mitigate CVE-2021-20095

Install update from vendor's website.

Babel - update to 2.9.1
Migration Toolkit for Containers - update to 1.7.4
python-babel-localedata (Ubuntu package) - addressed in versions 2.4.0+dfsg.1-2ubuntu1.1, 2.6.0+dfsg.1-1ubuntu2.2, 2.8.0+dfsg.1-4ubuntu0.1, 2.8.0+dfsg.1-6ubuntu0.1
python-babel (Ubuntu package) - addressed in versions 2.4.0+dfsg.1-2ubuntu1.1, 2.6.0+dfsg.1-1ubuntu2.2
python3-babel (Ubuntu package) - addressed in versions 2.4.0+dfsg.1-2ubuntu1.1, 2.6.0+dfsg.1-1ubuntu2.2, 2.8.0+dfsg.1-4ubuntu0.1, 2.8.0+dfsg.1-6ubuntu0.1
babel (Red Hat package) - update to 2.5.1-7.el8
python3-babel - update to 2.8.0-3
babel - update to 2.8.0-3
python2-babel - update to 2.8.0-3
babel-help - update to 2.8.0-3
babel - addressed in versions 2.8.0-4.fc32, 2.8.1-2.fc33
Red Hat OpenShift Container Platform - update to 4.11.0

External References

Related Security Bulletins