CVE-2021-28861

CVSS V2 None CVSS V3 High 7.4
Description
** DISPUTED ** Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Overview
  • CVE ID
  • CVE-2021-28861
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-08-23T01:15:07
  • Last Modified Date
  • 2022-12-09T16:44:47
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 1 OR 3.0.0 3.7.14
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 1 OR 3.8.0 3.8.14
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 1 OR 3.9.0 3.9.14
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 1 OR 3.10.0 3.10.6
cpe:2.3:a:python:python:3.11.0:alpha1:*:*:*:*:*:* 1 OR
cpe:2.3:a:python:python:3.11.0:alpha2:*:*:*:*:*:* 1 OR
cpe:2.3:a:python:python:3.11.0:alpha3:*:*:*:*:*:* 1 OR
cpe:2.3:a:python:python:3.11.0:alpha4:*:*:*:*:*:* 1 OR
cpe:2.3:a:python:python:3.11.0:alpha5:*:*:*:*:*:* 1 OR
cpe:2.3:a:python:python:3.11.0:alpha6:*:*:*:*:*:* 1 OR
cpe:2.3:a:python:python:3.11.0:alpha7:*:*:*:*:*:* 1 OR
cpe:2.3:a:python:python:3.11.0:beta1:*:*:*:*:*:* 1 OR
cpe:2.3:a:python:python:3.11.0:beta2:*:*:*:*:*:* 1 OR
cpe:2.3:a:python:python:3.11.0:beta3:*:*:*:*:*:* 1 OR
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* 1 OR
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* 1 OR
CVSS Version 3
  • Version
  • 3.1
  • Vector String
  • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
  • Attack Vector
  • NETWORK
  • Attack Compatibility
  • LOW
  • Privileges Required
  • NONE
  • User Interaction
  • REQUIRED
  • Scope
  • CHANGED
  • Confidentiality Impact
  • HIGH
  • Availability Impact
  • NONE
  • Base Score
  • 7.4
  • Base Severity
  • HIGH
  • Exploitability Score
  • 2.8
  • Impact Score
  • 4
References
Reference URL Reference Tags
https://bugs.python.org/issue43223 Issue Tracking Vendor Advisory
https://github.com/python/cpython/pull/24848 Patch Third Party Advisory
https://github.com/python/cpython/pull/93879 Patch Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2TRINJE3INWDVIHIABW4L2NP3RUSK7BJ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LTSPFIULY2GZJN3QYNFVM4JSU6H4D6J/ Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5OABQ5CMPQETJLFHROAXDIDXCMDTNVYG/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DISZAFSIQ7IAPAEQTC7G2Z5QUA2V2PSW/ Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HPX4XHT2FGVQYLY2STT2MRVENILNZTTU/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I3MQT5ZE3QH5PVDJMERTBOCILHK35CBE/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IFGV7P2PYFBMK32OKHCAC2ZPJQV5AUDF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KRGKPYA5YHIXQAMRIXO5DSCX7D4UUW4Q/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OKYE2DOI2X7WZXAWTQJZAXYIWM37HDCY/ Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QLE5INSVJUZJGY5OJXV6JREXWD7UDHYN/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S7G66SRWUM36ENQ3X6LAIG7HAB27D4XJ/ Mailing List Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TZEPOPUFC42KXXSLFPZ47ZZRGPOR7SQE/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WXF6MQ74HVIDDSR5AE2UDR24I6D4FEPC/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X46T4EFTIBXZRYTGASBDEZGYJINH2OWV/
History
Created Old Value New Value Data Type Notes
2022-08-23 02:00:05 Added to TrackCVE
2022-12-09 17:14:29 2022-12-09T16:44:47 CVE Modified Date updated
2022-12-09 17:14:29 Undergoing Analysis Analyzed Vulnerability Status updated