Alpine: multiple python3 packages: security update to 3.8.7-r3 (deprecated)

medium Tenable Cloud Security Plugin ID 400261

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before
3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and
urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query
parameters using a semicolon (;), they can cause a difference in the interpretation of the request between
the proxy (running with default configuration) and the server. This can result in malicious requests being
cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and
therefore would not include it in a cache key of an unkeyed parameter. (CVE-2021-23336)

See Also

https://git.alpinelinux.org/aports/commit/?id=3e257dd24335bc661f4a7f1eb9a8a64c565c7320

https://git.alpinelinux.org/aports/commit/?id=fc7ab1b9d897348c5a6672ce2019839288cdccd1

Plugin Details

Severity: Medium

ID: 400261

Version: Revision 1.29

Type: Local

Published: 8/16/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.63

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3.1

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2021-23336

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/15/2021

Vulnerability Publication Date: 2/15/2021

Reference Information

CVE: CVE-2021-23336

IAVA: 2021-A-0052-S