Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-33026
HistoryMay 13, 2021 - 12:00 a.m.

CVE-2021-33026

2021-05-1300:00:00
ubuntu.com
ubuntu.com
19

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.008 Low

EPSS

Percentile

81.7%

DISPUTED The Flask-Caching extension through 1.10.1 for Flask relies
on Pickle for serialization, which may lead to remote code execution or
local privilege escalation. If an attacker gains access to cache storage
(e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted
payload, poison the cache, and execute Python code. NOTE: a third party
indicates that exploitation is extremely unlikely unless the machine is
already compromised; in other cases, the attacker would be unable to write
their payload to the cache and generate the required collision.

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

0.008 Low

EPSS

Percentile

81.7%