• 公告ID (KylinSec-SA-2022-2028)

摘要:

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

安全等级: Low

公告ID: KylinSec-SA-2022-2028

发布日期: 2022年9月23日

关联CVE: CVE-2021-29921  

  • 详细介绍

1. 漏洞描述

   

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

2. 影响范围

cve名称 产品 组件 是否受影响
CVE-2021-29921 KY3.4-4A python-pip Unaffected
CVE-2021-29921 KY3.4-5 python-pip Unaffected
CVE-2021-29921 KY3.5.1 python-pip Unaffected

3. 影响组件

    无

4. 修复版本

    无

5. 修复方法

   无

6. 下载链接

    无
上一篇:KylinSec-SA-2022-2027 下一篇:KylinSec-SA-2022-2029