SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3737

An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time.

HIGH 7.5EPSS 11.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 11.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
11.59% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-835, CWE-400
Affected
python/python · redhat/codeready linux builder · redhat/codeready linux builder for ibm z systems · redhat/codeready linux builder for power little endian · redhat/enterprise linux · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for power little endian · fedoraproject/fedora · canonical/ubuntu linux · netapp/hci · netapp/management services for element software · netapp/netapp xcp smb · netapp/ontap select deploy administration utility · netapp/xcp nfs · oracle/communications cloud native core binding support function · oracle/communications cloud native core network exposure function · oracle/communications cloud native core policy
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.