Alpine: python3: security update to 3.9.4-r0

medium Tenable Cloud Security Plugin ID 406779

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince
another local or adjacent user to start a pydoc server could access the server and use it to disclose
sensitive information belonging to the other user that they would not normally be able to access. The
highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9,
Python versions before 3.9.3 and Python versions before 3.10.0a7. (CVE-2021-3426)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-3426

Plugin Details

Severity: Medium

ID: 406779

Version: Revision 1.31

Type: Local

Published: 10/31/2023

Updated: 2/3/2026

Supported Sensors: Agentless Assessment

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Low

Base Score: 2.7

Temporal Score: 2

Vector: CVSS2#AV:A/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2021-3426

CVSS v3

Risk Factor: Medium

Base Score: 5.7

Temporal Score: 5

Vector: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/7/2021

Reference Information

CVE: CVE-2021-3426

IAVA: 2021-A-0263-S