IP Address Information Corrected in Python 3.12.4 and 3.13.0a6
CVE-2024-4032

7.5HIGH

What is CVE-2024-4032?

The ipaddress module in CPython versions prior to 3.12.4 and 3.13.0a6 contained inaccuracies regarding the classification of IPv4 and IPv6 addresses as either 'globally reachable' or 'private'. This issue impacts the is_private and is_global properties of the ipaddress classes, leading to potential security implications. The module did not reflect the most up-to-date information from the IANA Special-Purpose Address Registries. Updated versions have rectified this issue, ensuring that address classifications are accurate and reliable.

Affected Version(s)

CPython 0 < 3.8.20

CPython 3.9.0 < 3.9.20

CPython 3.10.0 < 3.10.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-4032 : IP Address Information Corrected in Python 3.12.4 and 3.13.0a6