Path traversal in Babel - CVE-2021-42771

 

Path traversal in Babel - CVE-2021-42771

Published: August 12, 2022


Vulnerability identifier: #VU66467
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-42771
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to user compromise the affected system.

The vulnerability exists due to input validation error when processing directory traversal sequences within the locale .dat files in Babel.Locale. A remote user can load a malicious .dat file containing serialized Python objects and execute arbitrary code on the system.


Affected software

Babel
Amazon Linux AMI
Debian Linux
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Ansible Automation Platform
IBM Cloud Pak for Data System
python-babel
python-Babel
babel (Red Hat package)
python2-Babel
python3-Babel
python-babel (Debian package)
PowerStore T
IBM QRadar Incident Forensics
Contrail Networking

How to mitigate CVE-2021-42771

Install update from vendor's website.

Babel - update to 2.9.1
Migration Toolkit for Containers - update to 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
python-babel - update to 0.9.4-5.1.9
IBM Cloud Pak for Data System - update to 2.0.2.1.IF1
python-Babel - addressed in versions 2.3.4-4.3.1, 2.5.1-3.3.1, 2.5.3-4.8.1
babel (Red Hat package) - update to 2.5.1-7.el8
python2-Babel - addressed in versions 2.5.1-150000.3.3.1, 2.8.0-3.3.1
python3-Babel - addressed in versions 2.5.1-150000.3.3.1, 2.5.3-4.8.1, 2.8.0-3.3.1
python-babel (Debian package) - update to 2.6.0+dfsg.1-1+deb10u1
PowerStore T - update to 3.5.0.1-2083289
Red Hat OpenShift Container Platform - update to 4.11.0
IBM QRadar Incident Forensics - update to 7.5.0.10
Contrail Networking - update to 2011.L5

External References

Related Security Bulletins