CVE-2021-28861

EUVD-2021-15514
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
Affected Products (NVD)
VendorProductVersion
pythonpython
3.0.0 ≤
𝑥
< 3.7.14
pythonpython
3.8.0 ≤
𝑥
< 3.8.14
pythonpython
3.9.0 ≤
𝑥
< 3.9.14
pythonpython
3.10.0 ≤
𝑥
< 3.10.6
pythonpython
3.11.0:alpha1
pythonpython
3.11.0:alpha2
pythonpython
3.11.0:alpha3
pythonpython
3.11.0:alpha4
pythonpython
3.11.0:alpha5
pythonpython
3.11.0:alpha6
pythonpython
3.11.0:alpha7
pythonpython
3.11.0:beta1
pythonpython
3.11.0:beta2
pythonpython
3.11.0:beta3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pypy3
bookworm
7.3.11+dfsg-2+deb12u2
fixed
bullseye
unimportant
bullseye (security)
unimportant
sid
7.3.17+dfsg-2
fixed
trixie
7.3.17+dfsg-2
fixed
python2.7
bullseye
unimportant
python3.11
bookworm
3.11.2-6+deb12u2
fixed
bookworm (security)
3.11.2-6+deb12u3
fixed
python3.9
bullseye
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.7
bionic
not-affected
focal
not-affected
jammy
not-affected
kinetic
not-affected
lunar
dne
mantic
dne
trusty
not-affected
xenial
not-affected
python3.10
bionic
dne
focal
dne
jammy
Fixed 3.10.6-1~22.04.1
released
kinetic
not-affected
lunar
dne
mantic
dne
trusty
dne
xenial
dne
python3.11
bionic
dne
focal
dne
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
trusty
dne
xenial
dne
python3.4
bionic
dne
focal
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
trusty
not-affected
xenial
dne
python3.5
bionic
dne
focal
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
trusty
not-affected
xenial
Fixed 3.5.2-2ubuntu0~16.04.13+esm5
released
python3.6
bionic
not-affected
focal
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
trusty
dne
xenial
dne
python3.7
bionic
not-affected
focal
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
trusty
dne
xenial
dne
python3.8
bionic
not-affected
focal
not-affected
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
trusty
dne
xenial
dne
python3.9
bionic
dne
focal
Fixed 3.9.5-3ubuntu0~20.04.1+esm1
released
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
trusty
dne
xenial
dne
References