Aller au contenu
Appaloosa Scout

Vulnérabilité · NVD

CVE-2021-28861

HIGH 7.4 Échelle bulletin éditeur — CVSS NVD en attente

EN Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

Vecteur d'attaque : Réseau Aucun privilège requis
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
EPSS 2.03% au-dessus de la médiane percentile 79.2%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Python 3.12 Windows winget:Python.Python.3.12
    Affecté Corrigé Dernière suivie 3.12.10 indéterminé
Configurations CPE vulnérables (14)
Vendor Produit Versions
python python
Toutes plateformes (wildcard)
≥3.0.0 <3.7.14
python python
Toutes plateformes (wildcard)
≥3.8.0 <3.8.14
python python
Toutes plateformes (wildcard)
≥3.9.0 <3.9.14
python python
Toutes plateformes (wildcard)
≥3.10.0 <3.10.6
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
Voir sur NVD ↗ Advisory · bugs.python.org Advisory · github.com