ID

VAR-202109-1966


CVE

CVE-2021-3733


TITLE

Python Software Foundation  of  Python  Vulnerability related to resource exhaustion in products of multiple vendors

Trust: 0.8

sources: JVNDB: JVNDB-2021-018724

DESCRIPTION

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability. Python Software Foundation of Python Products from other vendors have resource exhaustion vulnerabilities.Service operation interruption (DoS) It may be in a state. Python is an open source, object-oriented programming language developed by the Python Foundation. The language is scalable, supports modules and packages, and supports multiple platforms. A code issue vulnerability exists in Python due to a failure in the product to properly handle RCFS. An attacker could exploit this vulnerability to cause a denial of service. The following products and versions are affected: python3.5 For Ubuntu 16.04 ESM. ========================================================================== Ubuntu Security Notice USN-5200-1 December 17, 2021 python3.7, python3.8 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Python could be made to crash if it receives specially crafted input from a malicious server. (CVE-2020-8492) It was discovered that the urllib.request.AbstractBasicAuthHandler class in Python contains regex with a quadratic worst-case time complexity. (CVE-2021-3737) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libpython3.7-stdlib 3.7.5-2ubuntu1~18.04.2 libpython3.8-stdlib 3.8.0-3ubuntu1~18.04.2 python3.7 3.7.5-2ubuntu1~18.04.2 python3.7-minimal 3.7.5-2ubuntu1~18.04.2 python3.8 3.8.0-3ubuntu1~18.04.2 python3.8-minimal 3.8.0-3ubuntu1~18.04.2 In general, a standard system update will make all the necessary changes. Bugs fixed (https://bugzilla.redhat.com/): 1948761 - CVE-2021-23369 nodejs-handlebars: Remote code execution when compiling untrusted compile templates with strict:true option 1956688 - CVE-2021-23383 nodejs-handlebars: Remote code execution when compiling untrusted compile templates with compat:true option 5. JIRA issues fixed (https://issues.jboss.org/): LOG-1858 - OpenShift Alerting Rules Style-Guide Compliance LOG-1917 - [release-5.1] Fluentd logs emit transaction failed: error_class=NoMethodError while forwarding to external syslog server 6. Summary: Red Hat Advanced Cluster Management for Kubernetes 2.4.0 General Availability release images, which fix several bugs and security issues. Description: Red Hat Advanced Cluster Management for Kubernetes 2.4.0 images Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. See the following Release Notes documentation, which will be updated shortly for this release, for additional details about this release: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_mana gement_for_kubernetes/2.4/html/release_notes/ Security fixes: * CVE-2021-33623: nodejs-trim-newlines: ReDoS in .end() method * CVE-2021-32626: redis: Lua scripts can overflow the heap-based Lua stack * CVE-2021-32627: redis: Integer overflow issue with Streams * CVE-2021-32628: redis: Integer overflow bug in the ziplist data structure * CVE-2021-32672: redis: Out of bounds read in lua debugger protocol parser * CVE-2021-32675: redis: Denial of service via Redis Standard Protocol (RESP) request * CVE-2021-32687: redis: Integer overflow issue with intsets * CVE-2021-32690: helm: information disclosure vulnerability * CVE-2021-32803: nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite * CVE-2021-32804: nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite * CVE-2021-23017: nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name * CVE-2021-3711: openssl: SM2 Decryption Buffer Overflow * CVE-2021-3712: openssl: Read buffer overruns processing ASN.1 strings * CVE-2021-3749: nodejs-axios: Regular expression denial of service in trim function * CVE-2021-41099: redis: Integer overflow issue with strings Bug fixes: * RFE ACM Application management UI doesn't reflect object status (Bugzilla #1965321) * RHACM 2.4 files (Bugzilla #1983663) * Hive Operator CrashLoopBackOff when deploying ACM with latest downstream 2.4 (Bugzilla #1993366) * submariner-addon pod failing in RHACM 2.4 latest ds snapshot (Bugzilla #1994668) * ACM 2.4 install on OCP 4.9 ipv6 disconnected hub fails due to multicluster pod in clb (Bugzilla #2000274) * pre-network-manager-config failed due to timeout when static config is used (Bugzilla #2003915) * InfraEnv condition does not reflect the actual error message (Bugzilla #2009204, 2010030) * Flaky test point to a nil pointer conditions list (Bugzilla #2010175) * InfraEnv status shows 'Failed to create image: internal error (Bugzilla #2010272) * subctl diagnose firewall intra-cluster - failed VXLAN checks (Bugzilla #2013157) * pre-network-manager-config failed due to timeout when static config is used (Bugzilla #2014084) 3. Bugs fixed (https://bugzilla.redhat.com/): 1963121 - CVE-2021-23017 nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name 1965321 - RFE ACM Application management UI doesn't reflect object status 1966615 - CVE-2021-33623 nodejs-trim-newlines: ReDoS in .end() method 1978144 - CVE-2021-32690 helm: information disclosure vulnerability 1983663 - RHACM 2.4.0 images 1990409 - CVE-2021-32804 nodejs-tar: Insufficient absolute path sanitization allowing arbitrary file creation and overwrite 1990415 - CVE-2021-32803 nodejs-tar: Insufficient symlink protection allowing arbitrary file creation and overwrite 1993366 - Hive Operator CrashLoopBackOff when deploying ACM with latest downstream 2.4 1994668 - submariner-addon pod failing in RHACM 2.4 latest ds snapshot 1995623 - CVE-2021-3711 openssl: SM2 Decryption Buffer Overflow 1995634 - CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings 1999784 - CVE-2021-3749 nodejs-axios: Regular expression denial of service in trim function 2000274 - ACM 2.4 install on OCP 4.9 ipv6 disconnected hub fails due to multicluster pod in clb 2003915 - pre-network-manager-config failed due to timeout when static config is used 2009204 - InfraEnv condition does not reflect the actual error message 2010030 - InfraEnv condition does not reflect the actual error message 2010175 - Flaky test point to a nil pointer conditions list 2010272 - InfraEnv status shows 'Failed to create image: internal error 2010991 - CVE-2021-32687 redis: Integer overflow issue with intsets 2011000 - CVE-2021-32675 redis: Denial of service via Redis Standard Protocol (RESP) request 2011001 - CVE-2021-32672 redis: Out of bounds read in lua debugger protocol parser 2011004 - CVE-2021-32628 redis: Integer overflow bug in the ziplist data structure 2011010 - CVE-2021-32627 redis: Integer overflow issue with Streams 2011017 - CVE-2021-32626 redis: Lua scripts can overflow the heap-based Lua stack 2011020 - CVE-2021-41099 redis: Integer overflow issue with strings 2013157 - subctl diagnose firewall intra-cluster - failed VXLAN checks 2014084 - pre-network-manager-config failed due to timeout when static config is used 5. Bugs fixed (https://bugzilla.redhat.com/): 1995656 - CVE-2021-36221 golang: net/http/httputil: panic due to racy read of persistConn after handler panic 2016256 - Release of OpenShift Serverless Eventing 1.19.0 2016258 - Release of OpenShift Serverless Serving 1.19.0 5. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: python27-python and python27-python-pip security update Advisory ID: RHSA-2022:1663-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2022:1663 Issue date: 2022-05-02 CVE Names: CVE-2021-3733 CVE-2021-3737 CVE-2021-4189 CVE-2022-0391 ===================================================================== 1. Summary: An update for python27-python and python27-python-pip is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: urllib: Regular expression DoS in AbstractBasicAuthHandler (CVE-2021-3733) * python: ftplib should not use the host from the PASV response (CVE-2021-4189) * python: urllib.parse does not sanitize URLs containing ASCII newline and tabs (CVE-2022-0391) * python: urllib: HTTP client possible infinite loop on a 100 Continue response (CVE-2021-3737) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1995162 - CVE-2021-3737 python: urllib: HTTP client possible infinite loop on a 100 Continue response 1995234 - CVE-2021-3733 python: urllib: Regular expression DoS in AbstractBasicAuthHandler 2036020 - CVE-2021-4189 python: ftplib should not use the host from the PASV response 2047376 - CVE-2022-0391 python: urllib.parse does not sanitize URLs containing ASCII newline and tabs 2064442 - SCL Python 2.7: pip contains bundled pre-built exe files in site-packages/pip/_vendor/distlib/ [rhscl-3.8.z] 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: python27-python-2.7.18-4.el7.src.rpm python27-python-pip-8.1.2-7.el7.src.rpm noarch: python27-python-pip-8.1.2-7.el7.noarch.rpm ppc64le: python27-python-2.7.18-4.el7.ppc64le.rpm python27-python-debug-2.7.18-4.el7.ppc64le.rpm python27-python-debuginfo-2.7.18-4.el7.ppc64le.rpm python27-python-devel-2.7.18-4.el7.ppc64le.rpm python27-python-libs-2.7.18-4.el7.ppc64le.rpm python27-python-test-2.7.18-4.el7.ppc64le.rpm python27-python-tools-2.7.18-4.el7.ppc64le.rpm python27-tkinter-2.7.18-4.el7.ppc64le.rpm s390x: python27-python-2.7.18-4.el7.s390x.rpm python27-python-debug-2.7.18-4.el7.s390x.rpm python27-python-debuginfo-2.7.18-4.el7.s390x.rpm python27-python-devel-2.7.18-4.el7.s390x.rpm python27-python-libs-2.7.18-4.el7.s390x.rpm python27-python-test-2.7.18-4.el7.s390x.rpm python27-python-tools-2.7.18-4.el7.s390x.rpm python27-tkinter-2.7.18-4.el7.s390x.rpm x86_64: python27-python-2.7.18-4.el7.x86_64.rpm python27-python-debug-2.7.18-4.el7.x86_64.rpm python27-python-debuginfo-2.7.18-4.el7.x86_64.rpm python27-python-devel-2.7.18-4.el7.x86_64.rpm python27-python-libs-2.7.18-4.el7.x86_64.rpm python27-python-test-2.7.18-4.el7.x86_64.rpm python27-python-tools-2.7.18-4.el7.x86_64.rpm python27-tkinter-2.7.18-4.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: python27-python-2.7.18-4.el7.src.rpm python27-python-pip-8.1.2-7.el7.src.rpm noarch: python27-python-pip-8.1.2-7.el7.noarch.rpm x86_64: python27-python-2.7.18-4.el7.x86_64.rpm python27-python-debug-2.7.18-4.el7.x86_64.rpm python27-python-debuginfo-2.7.18-4.el7.x86_64.rpm python27-python-devel-2.7.18-4.el7.x86_64.rpm python27-python-libs-2.7.18-4.el7.x86_64.rpm python27-python-test-2.7.18-4.el7.x86_64.rpm python27-python-tools-2.7.18-4.el7.x86_64.rpm python27-tkinter-2.7.18-4.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2021-3733 https://access.redhat.com/security/cve/CVE-2021-3737 https://access.redhat.com/security/cve/CVE-2021-4189 https://access.redhat.com/security/cve/CVE-2022-0391 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYm+vpdzjgjWX9erEAQhlcw//ZitWGk1VxkJDNg5smmlVjvp8LsG6KbQA Od/U//eUdDRby4jXSJKgcwR6Zg2ZEu0OFYhpNBpnK4WMaRFXmaO1QS7KGskNjDoF 5cJrw75snwtAwMLgEQ9GwA6uhvjpiSHuwukRU6TGDAWx+Bl/0BPuDm4nh0dSDvL9 nF3d5WrTSZqfgCN0bGTqy/xv+C8V5LVIe0a6niCVY/5X4oLfWBjdfn6WBU56xECR RFfyqN9QMoIFXrN3gvEA3U/p4OR9qDbh0h1MVGLIZqNEsiLn2Ypkmuk63X+V92Ez JernipmxsvSFEmg0jvQ+OXs6MaZgtvF91nUvQItn588tYXhlTpMeHPBV3s2HZNTW tNVs3ADONPsEofnt0CLqYrk0H+rkw/TxxUlZltuii8BAT6h7lMUAVe4AHc6WEleh qtwcdtfcH1RPvsN3GlN2qKKdtXN7lhVxKAdpz5hbo2Rcec1UVfyM/sxTxFHW1a6s dr0c6xTqQgq4PT86YmEZSjDMtAHrVrK9syeVdz30MiyS8Woz0yLr3avzpjVuMh+3 1jFSGSZA1RjRe1D/2c4q0yeRjV37nsvRj9YFtSUrxHBqdsF+ZKZRTKtqjPk1sjxi GNeYg7uxQ8w7aA/AHDk0Q5dPJOpoWx/7/RORbrF6wj5PT4dYaZMsv2zjP05w210j PsgdhVDyeR0= =Ica7 -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce

Trust: 2.25

sources: NVD: CVE-2021-3733 // JVNDB: JVNDB-2021-018724 // VULHUB: VHN-397442 // PACKETSTORM: 165361 // PACKETSTORM: 165363 // PACKETSTORM: 164993 // PACKETSTORM: 164948 // PACKETSTORM: 165053 // PACKETSTORM: 166913

AFFECTED PRODUCTS

vendor:fedoraprojectmodel:fedorascope:eqversion:34

Trust: 1.0

vendor:redhatmodel:codeready linux builder for ibm z systemsscope:eqversion:8.0

Trust: 1.0

vendor:redhatmodel:enterprise linux for ibm z systemsscope:eqversion:8.0

Trust: 1.0

vendor:redhatmodel:enterprise linux for ibm z systems eusscope:eqversion:8.4

Trust: 1.0

vendor:redhatmodel:enterprise linux server tusscope:eqversion:8.4

Trust: 1.0

vendor:redhatmodel:enterprise linux for power little endianscope:eqversion:8.0

Trust: 1.0

vendor:redhatmodel:codeready linux builder for power little endianscope:eqversion:8.0

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:36

Trust: 1.0

vendor:pythonmodel:pythonscope:eqversion:3.10.0

Trust: 1.0

vendor:pythonmodel:pythonscope:ltversion:3.8.10

Trust: 1.0

vendor:redhatmodel:enterprise linux server update services for sap solutionsscope:eqversion:8.4

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:33

Trust: 1.0

vendor:pythonmodel:pythonscope:gteversion:3.9.0

Trust: 1.0

vendor:redhatmodel:enterprise linux server ausscope:eqversion:8.4

Trust: 1.0

vendor:pythonmodel:pythonscope:ltversion:3.6.14

Trust: 1.0

vendor:netappmodel:ontap select deploy administration utilityscope:eqversion: -

Trust: 1.0

vendor:pythonmodel:pythonscope:gteversion:3.8.0

Trust: 1.0

vendor:redhatmodel:enterprise linux server for power little endian update services for sap solutionsscope:eqversion:8.4

Trust: 1.0

vendor:netappmodel:solidfire\, enterprise sds \& hci storage nodescope:eqversion: -

Trust: 1.0

vendor:fedoraprojectmodel:extra packages for enterprise linuxscope:eqversion:7.0

Trust: 1.0

vendor:redhatmodel:enterprise linux for power little endian eusscope:eqversion:8.4

Trust: 1.0

vendor:netappmodel:management services for element software and netapp hciscope:eqversion: -

Trust: 1.0

vendor:fedoraprojectmodel:fedorascope:eqversion:35

Trust: 1.0

vendor:pythonmodel:pythonscope:ltversion:3.9.5

Trust: 1.0

vendor:redhatmodel:codeready linux builderscope:eqversion:8.0

Trust: 1.0

vendor:redhatmodel:enterprise linux eusscope:eqversion:8.4

Trust: 1.0

vendor:pythonmodel:pythonscope:ltversion:3.7.11

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:8.0

Trust: 1.0

vendor:pythonmodel:pythonscope:gteversion:3.7.0

Trust: 1.0

vendor:netappmodel:hci compute nodescope:eqversion: -

Trust: 1.0

vendor:レッドハットmodel:red hat enterprise linux for ibm z systemsscope: - version: -

Trust: 0.8

vendor:fedoramodel:fedorascope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linux for power, little endian - update services for sap solutionsscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linux server ausscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linux for ibm z systems - extended update supportscope: - version: -

Trust: 0.8

vendor:netappmodel:solidfire enterprise sds & hci storage nodescope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linux server tusscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linuxscope: - version: -

Trust: 0.8

vendor:netappmodel:ontap select deploy administration utilityscope: - version: -

Trust: 0.8

vendor:pythonmodel:pythonscope: - version: -

Trust: 0.8

vendor:netappmodel:hci compute nodescope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linux for power, little endian - extended update supportscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linux eusscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linux server update services for sap solutionsscope: - version: -

Trust: 0.8

vendor:netappmodel:management software for element software and netapp hciscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:codeready linux builder for power little endianscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:codeready linux builder for ibm z systemsscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:codeready linux builderscope: - version: -

Trust: 0.8

vendor:fedoramodel:extra packages for enterprise linuxscope: - version: -

Trust: 0.8

vendor:レッドハットmodel:red hat enterprise linux for power, little endianscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2021-018724 // NVD: CVE-2021-3733

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-3733
value: MEDIUM

Trust: 1.0

NVD: CVE-2021-3733
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202109-1139
value: MEDIUM

Trust: 0.6

VULHUB: VHN-397442
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2021-3733
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-397442
severity: MEDIUM
baseScore: 4.0
vectorString: AV:N/AC:L/AU:S/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2021-3733
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2021-3733
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-397442 // CNNVD: CNNVD-202109-1139 // JVNDB: JVNDB-2021-018724 // NVD: CVE-2021-3733

PROBLEMTYPE DATA

problemtype:CWE-400

Trust: 1.1

problemtype:Resource exhaustion (CWE-400) [NVD evaluation ]

Trust: 0.8

sources: VULHUB: VHN-397442 // JVNDB: JVNDB-2021-018724 // NVD: CVE-2021-3733

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202109-1139

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-202109-1139

PATCH

title:SUSE Linux Enterprise Server Remediation of resource management error vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=171073

Trust: 0.6

sources: CNNVD: CNNVD-202109-1139

EXTERNAL IDS

db:NVDid:CVE-2021-3733

Trust: 3.9

db:PACKETSTORMid:164948

Trust: 0.8

db:PACKETSTORMid:165053

Trust: 0.8

db:PACKETSTORMid:165363

Trust: 0.8

db:PACKETSTORMid:164993

Trust: 0.8

db:JVNDBid:JVNDB-2021-018724

Trust: 0.8

db:PACKETSTORMid:167043

Trust: 0.7

db:PACKETSTORMid:164741

Trust: 0.7

db:PACKETSTORMid:164859

Trust: 0.7

db:CNNVDid:CNNVD-202109-1139

Trust: 0.7

db:PACKETSTORMid:166913

Trust: 0.7

db:AUSCERTid:ESB-2021.4095

Trust: 0.6

db:AUSCERTid:ESB-2023.3774

Trust: 0.6

db:AUSCERTid:ESB-2021.3941

Trust: 0.6

db:AUSCERTid:ESB-2022.1025

Trust: 0.6

db:AUSCERTid:ESB-2023.3839

Trust: 0.6

db:AUSCERTid:ESB-2021.4292

Trust: 0.6

db:AUSCERTid:ESB-2021.4172

Trust: 0.6

db:AUSCERTid:ESB-2021.3659

Trust: 0.6

db:AUSCERTid:ESB-2021.3138

Trust: 0.6

db:AUSCERTid:ESB-2022.2021

Trust: 0.6

db:AUSCERTid:ESB-2021.3979

Trust: 0.6

db:AUSCERTid:ESB-2021.3700

Trust: 0.6

db:AUSCERTid:ESB-2021.3813

Trust: 0.6

db:AUSCERTid:ESB-2021.4307

Trust: 0.6

db:AUSCERTid:ESB-2021.3589

Trust: 0.6

db:AUSCERTid:ESB-2021.4238

Trust: 0.6

db:AUSCERTid:ESB-2021.3519

Trust: 0.6

db:AUSCERTid:ESB-2022.0245

Trust: 0.6

db:AUSCERTid:ESB-2021.3878

Trust: 0.6

db:CS-HELPid:SB2022051144

Trust: 0.6

db:CS-HELPid:SB2022070422

Trust: 0.6

db:CS-HELPid:SB2022061211

Trust: 0.6

db:CS-HELPid:SB2021122214

Trust: 0.6

db:CS-HELPid:SB2022050235

Trust: 0.6

db:CS-HELPid:SB2021112309

Trust: 0.6

db:PACKETSTORMid:164190

Trust: 0.6

db:PACKETSTORMid:165361

Trust: 0.2

db:PACKETSTORMid:165008

Trust: 0.1

db:PACKETSTORMid:165337

Trust: 0.1

db:PACKETSTORMid:167023

Trust: 0.1

db:VULHUBid:VHN-397442

Trust: 0.1

sources: VULHUB: VHN-397442 // PACKETSTORM: 165361 // PACKETSTORM: 165363 // PACKETSTORM: 164993 // PACKETSTORM: 164948 // PACKETSTORM: 165053 // PACKETSTORM: 166913 // CNNVD: CNNVD-202109-1139 // JVNDB: JVNDB-2021-018724 // NVD: CVE-2021-3733

REFERENCES

url:https://security.netapp.com/advisory/ntap-20220407-0001/

Trust: 2.5

url:https://bugs.python.org/issue43075

Trust: 2.5

url:https://bugzilla.redhat.com/show_bug.cgi?id=1995234

Trust: 2.5

url:https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb

Trust: 2.5

url:https://github.com/python/cpython/pull/24391

Trust: 2.5

url:https://ubuntu.com/security/cve-2021-3733

Trust: 2.5

url:https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html

Trust: 2.4

url:https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html

Trust: 2.4

url:https://nvd.nist.gov/vuln/detail/cve-2021-3733

Trust: 1.4

url:https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html

Trust: 1.0

url:https://www.auscert.org.au/bulletins/esb-2022.0245

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2021112309

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3700

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2023.3839

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2021122214

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2021-3733/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3138

Trust: 0.6

url:https://packetstormsecurity.com/files/164859/red-hat-security-advisory-2021-4160-03.html

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022051144

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022050235

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.1025

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022070422

Trust: 0.6

url:https://packetstormsecurity.com/files/167043/red-hat-security-advisory-2022-1821-01.html

Trust: 0.6

url:https://packetstormsecurity.com/files/164741/red-hat-security-advisory-2021-4057-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3659

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3813

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3979

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3878

Trust: 0.6

url:https://packetstormsecurity.com/files/164190/ubuntu-security-notice-usn-5083-1.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3519

Trust: 0.6

url:https://packetstormsecurity.com/files/166913/red-hat-security-advisory-2022-1663-01.html

Trust: 0.6

url:https://packetstormsecurity.com/files/164948/red-hat-security-advisory-2021-4618-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.4307

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2023.3774

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3941

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.4238

Trust: 0.6

url:https://packetstormsecurity.com/files/165363/ubuntu-security-notice-usn-5199-1.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.3589

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022061211

Trust: 0.6

url:https://packetstormsecurity.com/files/165053/red-hat-security-advisory-2021-4766-01.html

Trust: 0.6

url:https://packetstormsecurity.com/files/164993/red-hat-security-advisory-2021-4628-01.html

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.4095

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.4172

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2022.2021

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2021.4292

Trust: 0.6

url:https://access.redhat.com/security/cve/cve-2021-3733

Trust: 0.4

url:https://listman.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.4

url:https://access.redhat.com/security/team/contact/

Trust: 0.4

url:https://bugzilla.redhat.com/):

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2021-3737

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2021-22947

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2021-33929

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2021-33930

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2021-33938

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2021-33929

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2021-22947

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2021-22946

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2021-33930

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2021-33928

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2021-22946

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2021-33938

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2021-33928

Trust: 0.3

url:https://access.redhat.com/security/cve/cve-2021-0512

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2021-3656

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2020-36385

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2020-36385

Trust: 0.2

url:https://access.redhat.com/security/cve/cve-2021-3656

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2021-0512

Trust: 0.2

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.2

url:https://launchpad.net/ubuntu/+source/python3.8/3.8.0-3ubuntu1~18.04.2

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2020-8492

Trust: 0.1

url:https://ubuntu.com/security/notices/usn-5200-1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/python3.7/3.7.5-2ubuntu1~18.04.2

Trust: 0.1

url:https://ubuntu.com/security/notices/usn-5199-1

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/python3.6/3.6.9-1~18.04ubuntu1.6

Trust: 0.1

url:https://issues.jboss.org/):

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-23369

Trust: 0.1

url:https://docs.openshift.com/container-platform/4.8/logging/cluster-logging-upgrading.html

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#low

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-23383

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-23369

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2021:4628

Trust: 0.1

url:https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-23383

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-32803

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-22924

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_mana

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-32626

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-32690

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-3711

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2021:4618

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-32675

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22922

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-37750

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-32675

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3712

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-32804

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-33623

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-23017

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-41099

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-36222

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-32804

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-32627

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-32672

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-32627

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-32690

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-32628

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-22922

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-36222

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-32626

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3711

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-32672

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-22923

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3749

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22924

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-33623

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-32687

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-23017

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-22923

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-3712

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-32687

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-32628

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-32803

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/openshift_container_platform/4.7/html/serverless/index

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/openshift_container_platform/4.8/html/serverless/index

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2021:4766

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/openshift_container_platform/4.6/html/serverless/index

Trust: 0.1

url:https://access.redhat.com/documentation/en-us/openshift_container_platform/4.9/html/serverless/index

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-36221

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-36221

Trust: 0.1

url:https://access.redhat.com/security/team/key/

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-3737

Trust: 0.1

url:https://access.redhat.com/articles/11258

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2022-0391

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2022-0391

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2021-4189

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2021-4189

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2022:1663

Trust: 0.1

sources: VULHUB: VHN-397442 // PACKETSTORM: 165361 // PACKETSTORM: 165363 // PACKETSTORM: 164993 // PACKETSTORM: 164948 // PACKETSTORM: 165053 // PACKETSTORM: 166913 // CNNVD: CNNVD-202109-1139 // JVNDB: JVNDB-2021-018724 // NVD: CVE-2021-3733

CREDITS

Red Hat

Trust: 0.4

sources: PACKETSTORM: 164993 // PACKETSTORM: 164948 // PACKETSTORM: 165053 // PACKETSTORM: 166913

SOURCES

db:VULHUBid:VHN-397442
db:PACKETSTORMid:165361
db:PACKETSTORMid:165363
db:PACKETSTORMid:164993
db:PACKETSTORMid:164948
db:PACKETSTORMid:165053
db:PACKETSTORMid:166913
db:CNNVDid:CNNVD-202109-1139
db:JVNDBid:JVNDB-2021-018724
db:NVDid:CVE-2021-3733

LAST UPDATE DATE

2026-08-28T21:46:22.298000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-397442date:2022-10-26T00:00:00
db:CNNVDid:CNNVD-202109-1139date:2023-07-10T00:00:00
db:JVNDBid:JVNDB-2021-018724date:2023-07-05T08:12:00
db:NVDid:CVE-2021-3733date:2026-06-17T04:05:39.570

SOURCES RELEASE DATE

db:VULHUBid:VHN-397442date:2022-03-10T00:00:00
db:PACKETSTORMid:165361date:2021-12-17T19:23:35
db:PACKETSTORMid:165363date:2021-12-17T19:23:51
db:PACKETSTORMid:164993date:2021-11-17T15:07:42
db:PACKETSTORMid:164948date:2021-11-12T17:01:04
db:PACKETSTORMid:165053date:2021-11-23T17:10:05
db:PACKETSTORMid:166913date:2022-05-02T15:26:53
db:CNNVDid:CNNVD-202109-1139date:2021-09-17T00:00:00
db:JVNDBid:JVNDB-2021-018724date:2023-07-05T00:00:00
db:NVDid:CVE-2021-3733date:2022-03-10T17:42:59.623