Description
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2790-1 | python-babel security update |
EUVD |
EUVD-2021-0032 | Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. |
Github GHSA |
GHSA-h4m5-qpfp-3mpv | Directory Traversal in Babel |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:38:50.154Z
Reserved: 2021-10-20T00:00:00.000Z
Link: CVE-2021-42771
No data.
Status : Modified
Published: 2021-10-20T21:15:07.930
Modified: 2024-11-21T06:28:08.413
Link: CVE-2021-42771
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA