CVE-2021-34141 describes an incomplete string comparison vulnerability in the numpy.core component of NumPy versions prior to 1.22.0, affecting various NumPy and Oracle Communications Cloud Native Core Policy products. This medium-severity vulnerability (CVSS 5.3) could allow attackers to trigger slightly incorrect data copying, resulting in a low impact on availability (A:L) without affecting confidentiality or integrity. The vendor considers this behavior "completely harmless," and there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.22.0CPE matchmatch criteria | cpe:2.3:a:numpy:numpy:*:*:*:*:*:*:*:* | ||
22.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-34141
Jan 11, 2022Incorrect Comparison in NumPy
Dec 18, 2021An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."
Dec 14, 2021numpy: incomplete string comparison in the numpy.core component
May 11, 2021