Safety vulnerability ID: 42203
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Babel 2.9.1 includes a fix for CVE-2021-42771: Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.
https://github.com/python-babel/babel/pull/782
Latest version: 2.16.0
Internationalization utilities
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution. See CVE-2021-42771.
MISC:https://github.com/python-babel/babel/pull/782: https://github.com/python-babel/babel/pull/782
MISC:https://lists.debian.org/debian-lts/2021/10/msg00040.html: https://lists.debian.org/debian-lts/2021/10/msg00040.html
MISC:https://www.tenable.com/security/research/tra-2021-14: https://www.tenable.com/security/research/tra-2021-14
MLIST:[debian-lts-announce] 20211021 [SECURITY] [DLA 2790-1] python-babel security update: https://lists.debian.org/debian-lts-announce/2021/10/msg00018.html
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application