MEDIUM · 6.5

CVE-2021-3733

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression De...

Vulnerability Description

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
PythonPython< 3.6.14
RedhatCodeready Linux Builder8.0
RedhatCodeready Linux Builder For Ibm Z Systems8.0
RedhatCodeready Linux Builder For Power Little Endian8.0
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Eus8.4
RedhatEnterprise Linux For Ibm Z Systems8.0
RedhatEnterprise Linux For Ibm Z Systems Eus8.4
RedhatEnterprise Linux For Power Little Endian8.0
RedhatEnterprise Linux For Power Little Endian Eus8.4
RedhatEnterprise Linux Server Aus8.4
RedhatEnterprise Linux Server For Power Little Endian Update Services For Sap Solutions8.4
RedhatEnterprise Linux Server Tus8.4
RedhatEnterprise Linux Server Update Services For Sap Solutions8.4
FedoraprojectExtra Packages For Enterprise Linux7.0
FedoraprojectFedora33
NetappManagement Services For Element Software And Netapp Hci-
NetappOntap Select Deploy Administration Utility-
NetappSolidfire\, Enterprise Sds \& Hci Storage Node-
NetappHci Compute Node Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3733?

CVE-2021-3733 is a vulnerability with a CVSS score of 6.5 (MEDIUM). There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression De...

How severe is CVE-2021-3733?

CVE-2021-3733 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3733?

Check the references section above for vendor advisories and patch information. Affected products include: Python Python, Redhat Codeready Linux Builder, Redhat Codeready Linux Builder For Ibm Z Systems, Redhat Codeready Linux Builder For Power Little Endian, Redhat Enterprise Linux.