SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3426

A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be…

MEDIUM 5.7EPSS 1.88%

Does this matter?

Lower severity and a low EPSS score (1.88%). Track it; it rarely justifies an emergency change on its own.

Description

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS 3.1
5.7 MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.88% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-22
Affected
python/python · fedoraproject/fedora · debian/debian linux · redhat/software collections · redhat/enterprise linux · netapp/cloud backup · netapp/ontap select deploy administration utility · netapp/snapcenter · oracle/communications cloud native core binding support function · oracle/zfs storage appliance kit
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.