← Back

CVE-2021-28861

nvd nist
Published: Aug 23, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 4.0
Source: NVD

Description

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

Affected (17)

1 product
Python
1 product
Fedora
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Python
From 3.0.0 to 3.7.14
From 3.10.0 to 3.10.6
From 3.8.0 to 3.8.14
From 3.9.0 to 3.9.14
Version 3.11.0 alpha1
Version 3.11.0 alpha2
Version 3.11.0 alpha3
Version 3.11.0 alpha4
Version 3.11.0 alpha5
Version 3.11.0 alpha6
Version 3.11.0 alpha7
Version 3.11.0 beta1
Version 3.11.0 beta2
Version 3.11.0 beta3
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36
Version 37

References (38)

Source: cve@mitre.org
Issue TrackingVendor Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.