Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-20T20:05:35

Updated: 2024-08-04T03:38:50.154Z

Reserved: 2021-10-20T00:00:00

Link: CVE-2021-42771

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-10-20T21:15:07.930

Modified: 2021-12-14T21:22:17.273

Link: CVE-2021-42771

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-04-28T00:00:00Z

Links: CVE-2021-42771 - Bugzilla