MGASA-2021-0267

Source
https://advisories.mageia.org/MGASA-2021-0267.html
Import Source
https://advisories.mageia.org/MGASA-2021-0267.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0267
Upstream
  • CVE-2021-20095
Published
2021-06-18T19:24:28Z
Modified
2026-04-16T04:44:26.857153566Z
Summary
Updated python-babel packages fix a security vulnerability
Details

Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code (CVE-2021-20095).

References
Credits

Affected packages

Mageia:7 / python-babel

Package

Name
python-babel
Purl
pkg:rpm/mageia/python-babel?arch=source&distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.0-2.1.mga7

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0267.json"

Mageia:8 / python-babel

Package

Name
python-babel
Purl
pkg:rpm/mageia/python-babel?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.1-1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0267.json"