Path traversal in Babel - CVE-2021-42771
Published: August 12, 2022
Vulnerability details
The vulnerability allows a remote attacker to user compromise the affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences within the locale .dat files in Babel.Locale. A remote user can load a malicious .dat file containing serialized Python objects and execute arbitrary code on the system.
Affected software
Amazon Linux AMI
Debian Linux
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Module for Public Cloud
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Python2
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Cloud Pak for Security (CP4S)
IBM Qradar SIEM
Ansible Automation Platform
IBM Cloud Pak for Data System
python-babel
python-Babel
babel (Red Hat package)
python2-Babel
python3-Babel
python-babel (Debian package)
PowerStore T
IBM QRadar Incident Forensics
Contrail Networking
How to mitigate CVE-2021-42771
Migration Toolkit for Containers - update to 1.7.4
Cloud Pak for Security (CP4S) - update to 1.10.7.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 10
python-babel - update to 0.9.4-5.1.9
IBM Cloud Pak for Data System - update to 2.0.2.1.IF1
python-Babel - addressed in versions 2.3.4-4.3.1, 2.5.1-3.3.1, 2.5.3-4.8.1
babel (Red Hat package) - update to 2.5.1-7.el8
python2-Babel - addressed in versions 2.5.1-150000.3.3.1, 2.8.0-3.3.1
python3-Babel - addressed in versions 2.5.1-150000.3.3.1, 2.5.3-4.8.1, 2.8.0-3.3.1
python-babel (Debian package) - update to 2.6.0+dfsg.1-1+deb10u1
PowerStore T - update to 3.5.0.1-2083289
Red Hat OpenShift Container Platform - update to 4.11.0
IBM QRadar Incident Forensics - update to 7.5.0.10
Contrail Networking - update to 2011.L5
External References
Related Security Bulletins
- Path traversal in Babel
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- SUSE update for python-Babel
- Multiple vulnerabilities in Juniper Networks Contrail Networking
- Red Hat Enterprise Linux 8 update for babel
- SUSE update for python-Babel
- SUSE update for python-Babel
- SUSE update for python-Babel
- SUSE update for python-Babel
- Debian update for python-babel
- Amazon Linux AMI update for python-babel
- Multiple vulnerabilities in Dell PowerStore Family
- Multiple vulnerabilities in IBM Cloud Pak for Security (CP4S)
- Multiple vulnerabilities in Red Hat Ansible Automation Platform 2.4
- Path traversal in IBM Cloud Pak for Data System
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in QRadar Incident Forensics
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- Red Hat Enterprise Linux 8 update for the python38:3.8 and python38-devel:3.8 modules