CVE-2021-3737
An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 11.59% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-835, CWE-400
- Affected
- python/python · redhat/codeready linux builder · redhat/codeready linux builder for ibm z systems · redhat/codeready linux builder for power little endian · redhat/enterprise linux · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for power little endian · fedoraproject/fedora · canonical/ubuntu linux · netapp/hci · netapp/management services for element software · netapp/netapp xcp smb · netapp/ontap select deploy administration utility · netapp/xcp nfs · oracle/communications cloud native core binding support function · oracle/communications cloud native core network exposure function · oracle/communications cloud native core policy
- Source
- secalert@redhat.com
References
- https://bugs.python.org/issue44022Exploit, Issue Tracking, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1995162Issue Tracking, Patch, Third Party Advisory
- https://github.com/python/cpython/pull/25916Patch, Third Party Advisory
- https://github.com/python/cpython/pull/26503Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.htmlPatch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220407-0009/Third Party Advisory
- https://ubuntu.com/security/CVE-2021-3737Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
- https://bugs.python.org/issue44022Exploit, Issue Tracking, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1995162Issue Tracking, Patch, Third Party Advisory
- https://github.com/python/cpython/pull/25916Patch, Third Party Advisory
- https://github.com/python/cpython/pull/26503Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
- https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html
- https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html
- https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.htmlPatch, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220407-0009/Third Party Advisory
- https://ubuntu.com/security/CVE-2021-3737Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.