VDB
DEBIAN-CVE-2021-28861
DEBIAN-CVE-2021-28861
PUBLISHED
CVSS 7.400000095367432 HIGH
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Risk Scores
CVSS v3.1
7.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | python3.9 | 3.9.2-1, 3.9.2-1, 0 |
| Debian:12 | python3.11 | 0, 0, 0 |
| Debian:13 | pypy3 | 0, 0, 0 |
| Debian:11 | python2.7 | 2.7.18-13, 0, 2.7.18-13.1~exp1 |
| Debian:12 | pypy3 | 0, 0, 0 |
| Debian:14 | pypy3 | 0, 0, 0 |
| Debian:11 | pypy3 | 7.3.5+dfsg-2+deb11u2, *, 0 |
Timeline
- Aug 23, 2022 CVE Published
- Apr 28, 2026 CVE Updated