Vulnérabilité · NVD
CVE-2021-28861
CVE-2021-28861, classée high par l'éditeur : 3 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.
- Gravité (CVSS)
- 7.4
- Exploitation
- 2.5 %
- Apps suivies
- 3
- Encore exposées
- 0
CVSS base ; la gravité est une note éditeur (échelle différente)
EPSS, prédiction à 30 jours
EN Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Voir le vecteur CVSS brut
Apps suivies liées à cette CVE
Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.
Configurations CPE vulnérables (14)
| Vendor | Produit | Plateforme | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.0.0 <3.7.14 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.8.0 <3.8.14 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.9.0 <3.9.14 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.10.0 <3.10.6 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:alpha1:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:alpha2:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:alpha3:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:alpha4:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:alpha5:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:alpha6:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:alpha7:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:beta1:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:beta2:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | - | cpe:2.3:a:python:python:3.11.0:beta3:*:*:*:*:*:* |