Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h7f6-hc46-frrv

Опубликовано: 24 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure.

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure.

Ссылки

EPSS

Процентиль: 63%
0.00468
Низкий

7.4 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 7.4
ubuntu
почти 3 года назад

** DISPUTED ** Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
redhat
почти 3 года назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
nvd
почти 3 года назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.4
debian
почти 3 года назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/h ...

EPSS

Процентиль: 63%
0.00468
Низкий

7.4 High

CVSS3

Дефекты

CWE-601