UBUNTU-CVE-2021-28861
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-28861
UBUNTU-CVE-2021-28861
Summary:
Details: Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
References: https://ubuntu.com/security/CVE-2021-28861, https://github.com/python/cpython/pull/93879, https://github.com/python/cpython/pull/24848, https://ubuntu.com/security/notices/USN-5629-1, https://ubuntu.com/security/notices/USN-5888-1, https://python-security.readthedocs.io/vuln/http-server-redirection.html, https://www.cve.org/CVERecord?id=CVE-2021-28861
Affected packages
Package
Name: python3.5
Purl: pkg:deb/ubuntu/[email protected]~16.04.13+esm5?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
