Server-Side Request Forgery (SSRF) in Python - CVE-2021-4189
Published: March 29, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input in the FTP (File Transfer Protocol) client library when using it in PASV (passive) mode. A remote attacker can set up a malicious FTP server, trick the FTP client in Python into connecting back to a given IP address and port, which can lead to FTP client scanning ports which otherwise would not have been possible.
Affected software
Amazon Linux AMI
SUSE Manager Proxy
SUSE Manager Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Module for Web Scripting
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Workstation Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module Python3
openEuler
Fedora
cflinuxfs3
OpenManage Network Integration (OMNI)
EMC ECS
Enterprise SONiC
Red Hat OpenShift Serverless
OpenShift Service Mesh
OpenShift Virtualization
Red Hat Software Collections
App Connect Enterprise Certified Container
Cryostat
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
Dell Secure Connect Gateway
Netcool Operations Insight
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Red Hat OpenStack
IBM Robotic Process Automation
Migration Toolkit for Containers
HPE Moonshot 1500 Chassis Manager
Red Hat OpenShift Container Platform
QRadar Suite
python27-python (Red Hat package)
python3 (Red Hat package)
python27-python-pip (Red Hat package)
python3.8-minimal (Ubuntu package)
python3.5-minimal (Ubuntu package)
python3.5 (Ubuntu package)
python3.11 (Ubuntu package)
python3.7-minimal (Ubuntu package)
python3.11-minimal (Ubuntu package)
python3.7 (Ubuntu package)
python3.6-minimal (Ubuntu package)
python3.9-minimal (Ubuntu package)
python3.6 (Ubuntu package)
python3.9 (Ubuntu package)
python3.8 (Ubuntu package)
python2.7-minimal (Ubuntu package)
python2.7 (Ubuntu package)
python2.7
python-base-debugsource
python-debuginfo
python-base-debuginfo-32bit
python-base-debuginfo
python-base-32bit
python-base
python-32bit
python
libpython2_7-1_0-debuginfo-32bit
libpython2_7-1_0-debuginfo
libpython2_7-1_0-32bit
libpython2_7-1_0
python-doc-pdf
python-doc
python-curses-debuginfo
python-xml-debuginfo
python-xml
python-tk-debuginfo
python-tk
python-idle
python-gdbm-debuginfo
python-gdbm
python-devel
python-demo
python-debugsource
python-debuginfo-32bit
python-curses
python3.4 (Ubuntu package)
python3.4-minimal (Ubuntu package)
python3-devel
python3-devel-debuginfo
libpython3_4m1_0-32bit
libpython3_4m1_0
libpython3_4m1_0-debuginfo
python3-base
python3-base-debugsource
python3-base-debuginfo
libpython3_4m1_0-debuginfo-32bit
python3-base-debuginfo-32bit
python3-dbm
python3-dbm-debuginfo
python3-debugsource
python3
python3-curses
python3-curses-debuginfo
python3-tk
python3-debuginfo
python3-tk-debuginfo
python3-tkinter
python3-test
python3-libs
python3-idle
platform-python-devel
platform-python-debug
platform-python
python3-debug
python3-help
python3.10-minimal (Ubuntu package)
python3.10 (Ubuntu package)
python3.12-minimal (Ubuntu package)
python3.12 (Ubuntu package)
Cloud Pak for Security (CP4S)
Dell Enterprise SONiC Distribution
Junos Space Security Director
How to mitigate CVE-2021-4189
cflinuxfs3 - update to 0.279.0
Red Hat OpenShift Serverless - update to 1.22.1
App Connect Enterprise Certified Container - addressed in versions 1.1.10, 4.2.0
Migration Toolkit for Containers - addressed in versions 1.6.5, 1.7.2, 1.7.4
QRadar Suite - update to 1.10.17.0
Cryostat - update to 2.1.1
OpenShift Service Mesh - update to 2.1.3
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.11, 2.4.5, 2.5.0
python27-python (Red Hat package) - update to 2.7.18-4.el7
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.68.2, 3.69.2, 3.70
python3 (Red Hat package) - update to 3.6.8-45.el8
Dell Secure Connect Gateway - update to 5.12.00.10
python27-python-pip (Red Hat package) - update to 8.1.2-7.el7
python3.8-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.10-0ubuntu1~20.04.4, 3.8.10-0ubuntu1~20.04.10
python3.5-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.5.2-2ubuntu0~16.04.13
python3.5 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 3.5.2-2ubuntu0~16.04.13
python3.11 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.7-minimal (Ubuntu package) - update to Ubuntu Pro
python3.11-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.11.6-3ubuntu0.1
python3.7 (Ubuntu package) - update to Ubuntu Pro
python3.6-minimal (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.7
python3.9-minimal (Ubuntu package) - update to Ubuntu Pro
python3.6 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.6.9-1~18.04ubuntu1.7
python3.9 (Ubuntu package) - update to Ubuntu Pro
python3.8 (Ubuntu package) - addressed in versions Ubuntu Pro, 3.8.10-0ubuntu1~20.04.4, 3.8.10-0ubuntu1~20.04.10
Netcool Operations Insight - update to 1.6.7
Cloud Pak for Security (CP4S) - update to 1.10.10.0
python2.7-minimal (Ubuntu package) - update to 2.7.17-1~18.04ubuntu1.7
python2.7 (Ubuntu package) - update to 2.7.17-1~18.04ubuntu1.7
python2.7 - addressed in versions 2.7.18-20.fc34, 2.7.18-20.fc35, 2.7.18-20.fc37
python-base-debugsource - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-base-debuginfo-32bit - update to 2.7.18-33.8.1
python-base-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-base-32bit - update to 2.7.18-33.8.1
python-base - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-32bit - update to 2.7.18-33.8.1
python - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
libpython2_7-1_0-debuginfo-32bit - update to 2.7.18-33.8.1
libpython2_7-1_0-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
libpython2_7-1_0-32bit - update to 2.7.18-33.8.1
libpython2_7-1_0 - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-doc-pdf - update to 2.7.18-33.8.1
python-doc - update to 2.7.18-33.8.1
python-curses-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-xml-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-xml - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-tk-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-tk - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-idle - update to 2.7.18-33.8.1
python-gdbm-debuginfo - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-gdbm - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-devel - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.2
python-demo - update to 2.7.18-33.8.1
python-debugsource - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python-debuginfo-32bit - update to 2.7.18-33.8.1
python-curses - addressed in versions 2.7.18-33.8.1, 2.7.18-150000.38.1
python3.4 (Ubuntu package) - update to 3.4.3
python3.4-minimal (Ubuntu package) - update to 3.4.3-1ubuntu1~14.04.7
python3-devel - update to 3.4.10-25.85.1
python3-devel-debuginfo - update to 3.4.10-25.85.1
libpython3_4m1_0-32bit - update to 3.4.10-25.85.1
libpython3_4m1_0 - update to 3.4.10-25.85.1
libpython3_4m1_0-debuginfo - update to 3.4.10-25.85.1
python3-base - update to 3.4.10-25.85.1
python3-base-debugsource - update to 3.4.10-25.85.1
python3-base-debuginfo - update to 3.4.10-25.85.1
libpython3_4m1_0-debuginfo-32bit - update to 3.4.10-25.85.1
python3-base-debuginfo-32bit - update to 3.4.10-25.85.1
python3-dbm - update to 3.4.10-25.85.2
python3-dbm-debuginfo - update to 3.4.10-25.85.2
python3-debugsource - update to 3.4.10-25.85.2
python3 - update to 3.4.10-25.85.2
python3-curses - update to 3.4.10-25.85.2
python3-curses-debuginfo - update to 3.4.10-25.85.2
python3-tk - update to 3.4.10-25.85.2
python3-debuginfo - update to 3.4.10-25.85.2
python3-tk-debuginfo - update to 3.4.10-25.85.2
python3-tkinter - update to 3.6.8-45.0.1
python3-test - update to 3.6.8-45.0.1
python3-libs - update to 3.6.8-45.0.1
python3-idle - update to 3.6.8-45.0.1
platform-python-devel - update to 3.6.8-45.0.1
platform-python-debug - update to 3.6.8-45.0.1
platform-python - update to 3.6.8-45.0.1
OpenManage Network Integration (OMNI) - update to 3.7
EMC ECS - update to 3.7.0.2
python3-debugsource - update to 3.7.9-20
python3-debug - update to 3.7.9-20
python3-help - update to 3.7.9-20
python3-debuginfo - update to 3.7.9-20
python3-devel - update to 3.7.9-20
python3 - update to 3.7.9-20
python3.10-minimal (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.10 (Ubuntu package) - update to 3.10.12-1~22.04.4
python3.12-minimal (Ubuntu package) - update to 3.12.0-1ubuntu0.1
python3.12 (Ubuntu package) - update to 3.12.0-1ubuntu0.1
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Enterprise SONiC - update to 4.1.2
Dell Enterprise SONiC Distribution - update to 4.4.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
Red Hat OpenShift Container Platform - update to 4.11.0
OpenShift Virtualization - update to 4.11.0
Red Hat OpenStack - update to 16.2.z
IBM Robotic Process Automation - update to 21.0.3
Junos Space Security Director - update to 24.1R3
External References
Related Security Bulletins
- SSRF in Python
- Ubuntu update for python2.7
- Multiple vulnerabilities in cflinuxfs3
- Red Hat Software Collections update for python27-python and python27-python-pip
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- Red Hat Enterprise Linux 8 update for python3
- Multiple vulnerabilities in OpenShift Serverless
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes
- Amazon Linux AMI update for python27
- Multiple vulnerabilities in Cryostat
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.1
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes (RHACS)
- SSRF in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes (RHACS)
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.3
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in Red Hat OpenStack 16.2
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in OpenShift Virtualization
- Multiple vulnerabilities in Dell Elastic Cloud Storage (ECS)
- Server-side request forgery in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- SUSE update for python3
- SUSE update for python
- SUSE update for python
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in IBM QRadar Suite software
- Multiple vulnerabilities in Dell EMC Enterprise SONiC
- openEuler update for python3
- Ubuntu update for python3.10
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Multiple vulnerabilities in Migration Toolkit for Containers 1.6
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2
- Fedora 37 update for python2.7
- Fedora 34 update for python2.7
- Fedora 35 update for python2.7
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Anolis OS update for python3
- Multiple vulnerabilities in Dell Enterprise SONiC Distribution
- Multiple vulnerabilities in Junos Space Security Director Policy Enforcer module