CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.4 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
VendorProductVersion
pythonpython
3.0.0 ≤
𝑥
< 3.7.14
pythonpython
3.8.0 ≤
𝑥
< 3.8.14
pythonpython
3.9.0 ≤
𝑥
< 3.9.14
pythonpython
3.10.0 ≤
𝑥
< 3.10.6
pythonpython
3.11.0:alpha1
pythonpython
3.11.0:alpha2
pythonpython
3.11.0:alpha3
pythonpython
3.11.0:alpha4
pythonpython
3.11.0:alpha5
pythonpython
3.11.0:alpha6
pythonpython
3.11.0:alpha7
pythonpython
3.11.0:beta1
pythonpython
3.11.0:beta2
pythonpython
3.11.0:beta3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pypy3
bullseye (security)
unimportant
bullseye
unimportant
bookworm
7.3.11+dfsg-2+deb12u2
fixed
sid
7.3.17+dfsg-2
fixed
trixie
7.3.17+dfsg-2
fixed
python2.7
bullseye
unimportant
python3.11
bookworm
3.11.2-6+deb12u2
fixed
bookworm (security)
3.11.2-6+deb12u3
fixed
python3.9
bullseye
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.7
mantic
dne
lunar
dne
kinetic
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
not-affected
python3.10
mantic
dne
lunar
dne
kinetic
not-affected
jammy
Fixed 3.10.6-1~22.04.1
released
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.11
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
focal
dne
bionic
dne
xenial
dne
trusty
dne
python3.4
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
dne
trusty
not-affected
python3.5
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
dne
xenial
Fixed 3.5.2-2ubuntu0~16.04.13+esm5
released
trusty
not-affected
python3.6
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
not-affected
xenial
dne
trusty
dne
python3.7
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
dne
bionic
not-affected
xenial
dne
trusty
dne
python3.8
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
not-affected
bionic
not-affected
xenial
dne
trusty
dne
python3.9
mantic
dne
lunar
dne
kinetic
dne
jammy
dne
focal
Fixed 3.9.5-3ubuntu0~20.04.1+esm1
released
bionic
dne
xenial
dne
trusty
dne
References