CVE-2026-8328
בינונית 5.9
תיאור (מקור, אנגלית)
The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.
מדדים
- CVSS 4.0
-
5.9 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-30/9/2026
- CWE
- CWE-918
קישורים
- https://github.com/python/cpython/commit/2bbcf3fb7a420a05605576c0f9468d4675381…
- https://github.com/python/cpython/commit/5dadc64673ce875ebfb24163907777dae0f6c…
- https://github.com/python/cpython/commit/7d95a1dc7382b55cba7fdd6a110336077584a…
- https://github.com/python/cpython/commit/bb3446dda6c49b32e67c11dbbbf221b40be00…
- https://github.com/python/cpython/commit/c88704431ea3248ca769384c13856330976fa…
- https://github.com/python/cpython/commit/eac4fe3b2c77693790a5ef7dfab127c1fee81…
- https://github.com/python/cpython/commit/ef12d0dc824baccf737bba1458e5eed3d1e0f…
- https://github.com/python/cpython/issues/87451
- https://github.com/python/cpython/pull/149648
- https://mail.python.org/archives/list/[email protected]/thread/ITF2…