In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOracle Communications Cloud Native Core Automated Test Suite
APPOracle1.8.0Oracle Communications Cloud Native Core Binding Support Function
APPOracle1.11.0Oracle Communications Cloud Native Core Network Slice Selection Function
APPOracle1.8.0Oracle Graalvm
APPOracle20.3.221.1.0Oracle Zfs Storage Appliance Kit
APPOracle8.8Python
APPPython3.9.0 – 3.9.5 (excl.)3.8.0 – 3.8.12 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓same product
RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression
CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓same product
RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2017-1000353CRITICAL9.8⚠ KEVPL ✓same product
Jenkins CLI — nieuwierzytelnione RCE przez deserializację SignedObject