CVE-2021-28861

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-28861
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28861.json
Aliases
Related
Withdrawn
2023-05-03T00:00:00Z
Published
2022-08-23T01:15:07Z
Modified
2023-12-06T01:01:02.104627Z
Details

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

References

Affected packages

Git / github.com/python/cpython

Affected versions

v3.*

v3.8.0
v3.8.1
v3.8.10
v3.8.11
v3.8.12
v3.8.13
v3.8.1rc1
v3.8.2
v3.8.2rc1
v3.8.2rc2
v3.8.3
v3.8.3rc1
v3.8.4
v3.8.4rc1
v3.8.5
v3.8.6
v3.8.6rc1
v3.8.7
v3.8.7rc1
v3.8.8
v3.8.8rc1
v3.8.9