Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-28861

Опубликовано: 22 авг. 2022
Источник: redhat
CVSS3: 7.4

Описание

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

A vulnerability was found in python. This security flaw causes an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of the URI path. This issue may lead to information disclosure.

Отчет

This vulnerability is rated as a moderate because in Python's http.server module, an input validation flaw in lib/http/server.py allows for an open redirection. This issue is triggered when a remote, unauthenticated attacker (Attack Vector: Network, Privileges Required: None) convinces a user to access a crafted URL that begins with two forward slashes (//) leads to an information disclosure. Versions of python36:3.6/python36 as shipped with Red Hat Enterprise Linux 8 are marked as 'Not affected' as they just provide "symlinks" to the main python3 component, which provides the actual interpreter of the Python programming language.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6pythonNot affected
Red Hat Enterprise Linux 7pythonNot affected
Red Hat Enterprise Linux 7python3Out of support scope
Red Hat Enterprise Linux 8python2Not affected
Red Hat Enterprise Linux 8python27:2.7/python2Not affected
Red Hat Enterprise Linux 8python36Not affected
Red Hat Enterprise Linux 8python36:3.6/python36Not affected
Red Hat Enterprise Linux 8python38Affected
Red Hat Enterprise Linux 8python3FixedRHSA-2023:083321.02.2023
Red Hat Enterprise Linux 8python38FixedRHSA-2023:276316.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2120642python: open redirection vulnerability in lib/http/server.py may lead to information disclosure

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
nvd
около 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
msrc
около 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

CVSS3: 7.4
debian
около 3 лет назад

Python 3.x through 3.10 has an open redirection vulnerability in lib/h ...

suse-cvrf
почти 3 года назад

Security update for python

7.4 High

CVSS3