PT-2021-23584 · Dask · Dask

Jcrist

·

Published

2021-10-26

·

Updated

2026-06-16

·

CVE-2021-42343

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dask versions prior to 2021.10.0
Description An issue was discovered in Dask where single machine Dask clusters started with dask.distributed.LocalCluster or dask.distributed.Client would mistakenly configure their respective Dask workers to listen on external interfaces rather than only on localhost. A Dask cluster created using this method could be used by a sophisticated attacker to achieve remote code execution if the machine has an applicable port exposed.
Recommendations For versions prior to 2021.10.0, update to version 2021.10.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Dask workers to minimize the risk of exploitation. Avoid using dask.distributed.LocalCluster or dask.distributed.Client on machines with exposed ports until the issue is resolved.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42343
GHSA-HWQR-F3V9-HWXR
GHSA-J8FQ-86C5-5V2R
OPENSUSE-SU-2024:11766-1
OPENSUSE-SU-2024:13920-1
OPENSUSE-SU-2026:11043-1
PYSEC-2021-387
PYSEC-2021-871
PYSEC-2021-872

Affected Products

Dask