CVE-2021-28861

HIGH

Python 3.0.0-3.10 - Open Redirect via URI Path

Title source: llm
STIX 2.1

Description

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

References (20)

Core 20
Core References
Patch, Third Party Advisory
https://github.com/python/cpython/pull/24848
Issue Tracking, Vendor Advisory
https://bugs.python.org/issue43223
Patch, Third Party Advisory
https://github.com/python/cpython/pull/93879
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202305-02

Scores

CVSS v3 7.4
EPSS 0.0140
EPSS Percentile 80.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (5)
fedoraproject/fedora 35
fedoraproject/fedora 36
fedoraproject/fedora 37
python/python 3.11.0 alpha1 (10 CPE variants)
python/python 3.0.0 - 3.7.14
Published Aug 23, 2022
Tracked Since Feb 18, 2026