QID 355079
Date Published: 2023-05-18
QID 355079: Amazon Linux Security Advisory for babel : AL2012-2023-403
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2021-42771:
A flaw was found in python-babel. A path traversal vulnerability was found in how locale data files are checked and loaded within python-babel, allowing a local attacker to trick an application that uses python-babel to load a file outside of the intended locale directory. The highest threat from this vulnerability is to data confidentiality and integrity as well as service availability.
1955615: CVE-2021-20095 CVE-2021-42771 python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary code
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
CVEs related to QID 355079
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-403 | Amazon Linux Bare Metal |
|