Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-28861

Опубликовано: 22 авг. 2022
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

A vulnerability was found in python. This security flaw causes an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of the URI path. This issue may lead to information disclosure.

Отчет

This vulnerability is rated as a moderate because in Python's http.server module, an input validation flaw in lib/http/server.py allows for an open redirection. This issue is triggered when a remote, unauthenticated attacker (Attack Vector: Network, Privileges Required: None) convinces a user to access a crafted URL that begins with two forward slashes (//) leads to an information disclosure. Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6pythonNot affected
Red Hat Enterprise Linux 7pythonNot affected
Red Hat Enterprise Linux 7python3Out of support scope
Red Hat Enterprise Linux 8python2Not affected
Red Hat Enterprise Linux 8python27:2.7/python2Not affected
Red Hat Enterprise Linux 8python36Not affected
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Enterprise Linux 8python38Affected
Red Hat Enterprise Linux 8python3FixedRHSA-2023:083321.02.2023
Red Hat Enterprise Linux 8python38FixedRHSA-2023:276316.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2120642python: open redirection vulnerability in lib/http/server.py may lead to information disclosure

EPSS

Процентиль: 80%
0.01395
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
nvd
больше 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
msrc
больше 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
debian
больше 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/h ...

suse-cvrf
около 3 лет назад

Security update for python

EPSS

Процентиль: 80%
0.01395
Низкий

7.4 High

CVSS3