CVE-2021-42771

Name
CVE-2021-42771
Description
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://www.tenable.com/security/research/tra-2021-14
MISC https://lists.debian.org/debian-lts/2021/10/msg00040.html
MISC https://github.com/python-babel/babel/pull/782
MLIST https://lists.debian.org/debian-lts-announce/2021/10/msg00018.html
Third Party Advisory https://www.debian.org/security/2021/dsa-5018

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:pocoo:babel:*:*:*:*:*:*:*:* babel >= None < 2.9.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status