← Back

CVE-2021-3426

nvd nist
Published: May 20, 2021Modified: Dec 18, 2025

JSON object

Loading...
5.7
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.1 / Impact: 3.6
Source: NVD

Description

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

Affected (22)

Products: Python: Python · Fedoraproject: Fedora · Debian: Debian Linux · +3 more
Show all products
1 product
Python
1 product
Fedora
1 product
Debian Linux
2 products
Enterprise Linux
Software Collections
3 products
Cloud Backup
Snapcenter
2 products
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Python
Before 2.7.18
From 3.6.0 to 3.6.13
From 3.7.0 to 3.7.10
From 3.8.0 to 3.8.8
From 3.9.0 to 3.9.3
Version 3.10.0 alpha1
Version 3.10.0 alpha2
Version 3.10.0 alpha3
Version 3.10.0 alpha4
Version 3.10.0 alpha5
Version 3.10.0 alpha6
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 32
Version 33
Version 34
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
All versions
Configuration E
3 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
Configuration F
2 vulnerable

References (29)

Source: secalert@redhat.com
Issue TrackingPatchThird Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.