CVE-2021-20095 log

Source
Severity Medium
Remote No
Type Arbitrary code execution
Description
Relative Path Traversal in Babel 2.9.0 allows an attacker to load arbitrary locale files on disk and execute arbitrary code.
Group Package Affected Fixed Severity Status Ticket
AVG-1894 python-babel 2.9.0-1 2.9.1-1 Medium Fixed
Date Advisory Group Package Severity Type
19 May 2021 ASA-202105-15 AVG-1894 python-babel Medium arbitrary code execution
References
https://www.tenable.com/security/research/tra-2021-14
https://github.com/python-babel/babel/pull/782
https://github.com/python-babel/babel/commit/412015ef642bfcc0d8ba8f4d05cdbb6aac98d9b3