CVE-2024-4032

Aliases:DEBIAN-CVE-2024-4032UBUNTU-CVE-2024-4032ALPINE-CVE-2024-4032CGA-8qf3-8vm2-5c8xCGA-9m3q-8fq8-cprwCGA-jxg7-hf4h-jhqgCGA-mvpc-r5mm-fwf9CGA-97cp-mqg9-376hCGA-fjv5-mvmg-x652CGA-wf8w-wcpx-7v74CGA-wfwc-jr69-692c
Advisory lineage Upstream: 0 Downstream: 43
Deferred
Published: 17 Jun 2024, 15:05
Last modified:03 Nov 2025, 21:57

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
1.08% LOW
1% probability -0.05%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

17 Jun 2024, 15:05
Published
Vulnerability first disclosed
03 Nov 2025, 21:57
Last Modified
Vulnerability information updated

Description

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 1.08% Percentile: 64%

Techniques & Countermeasures

  • CWE-697Incorrect Comparison

    The product compares two entities in a security-relevant context, but the comparison is incorrect.

Affected Systems

  • alpinepython3

    < 3.10.15-r0 | < 3.11.10-r0 | < 3.11.10-r0 | < 3.12.6-r0 | < 3.12.6-r0 | < 3.12.6-r0 | < 3.12.6-r0 | < 3.12.6-r0

  • chainguardpython-3.10

    < 3.10.14-r4

  • chainguardpython-3.11

    < 3.11.9-r4

  • chainguardpython-3.12

    < 3.12.4-r0

  • chainguardpython-3.9

    < 3.9.19-r2

  • wolfipython-3.10

    < 3.10.14-r4

  • wolfipython-3.11

    < 3.11.9-r4

  • wolfipython-3.12

    < 3.12.4-r0

  • debianpypy3

    all | all | < 7.3.18+dfsg-1 | < 7.3.18+dfsg-1

  • debianpython3.11

    < 3.11.2-6+deb12u3

  • debianpython3.9

    < 3.9.2-1+deb11u2

  • ubuntupython3.10

    < 3.10.12-1~22.04.5

  • ubuntupython3.11

    all | all

  • ubuntupython3.12

    < 3.12.3-1ubuntu0.1

  • ubuntupython3.4

    all

  • ubuntupython3.5

    < 3.5.2-2ubuntu0~16.04.4~14.04.1+esm4 | < 3.5.2-2ubuntu0~16.04.13+esm16

  • ubuntupython3.6

    all

  • ubuntupython3.7

    all

  • ubuntupython3.8

    all | < 3.8.10-0ubuntu1~20.04.11

  • ubuntupython3.9

    all

  • python software foundationcpython

    < 3.8.20 | ≥ 3.9.0, < 3.9.20 | ≥ 3.10.0, < 3.10.15 | ≥ 3.11.0, < 3.11.10 | ≥ 3.12.0, < 3.12.4 | ≥ 3.13.0a1, < 3.13.0a6

References (25)