PT-2021-3603 · Python+9 · Python+9

Published

2020-05-05

·

Updated

2025-11-07

·

CVE-2021-3426

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Python versions prior to 3.8.9 Python versions prior to 3.9.3 Python versions prior to 3.10.0a7
Description The issue is related to a flaw in Python 3's pydoc, which could allow a local or adjacent attacker to access sensitive information belonging to another user by starting a pydoc server. This flaw poses a high risk to data confidentiality.
Recommendations For versions prior to 3.8.9, update to version 3.8.9 or later. For versions prior to 3.9.3, update to version 3.9.3 or later. For versions prior to 3.10.0a7, update to version 3.10.0a7 or later.

Exploit

Fix

Information Disclosure

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4160
ALSA-2021:4162
ALSA-2021:4399
ALT-PU-2020-1914
ALT-PU-2020-3318
ALT-PU-2020-3323
ALT-PU-2021-1596
ALT-PU-2021-2653
ALT-PU-2024-3474
BDU:2021-03708
BIT-LIBPYTHON-2021-3426
BIT-PYTHON-2021-3426
BIT-PYTHON-MIN-2021-3426
CESA-2021_4160
CESA-2021_4162
CESA-2021_4399
CVE-2021-3426
DLA-2619-1
DLA-3477-1
DLA-3980-1
MGASA-2021-0193
OESA-2021-1264
OPENSUSE-SU-2021:4104-1
OPENSUSE-SU-2021_4104-1
OPENSUSE-SU-2024:11283-1
OPENSUSE-SU-2024:11284-1
OPENSUSE-SU-2024:11285-1
OPENSUSE-SU-2024:11286-1
OPENSUSE-SU-2024:12089-1
OPENSUSE-SU-2024:12910-1
OPENSUSE-SU-2024:14109-1
OPENSUSE-SU-2024:14434-1
OPENSUSE-SU-2025:15713-1
PSF-2021-4
RHSA-2021:3254
RHSA-2021:4160
RHSA-2021:4162
RHSA-2021:4399
RHSA-2021_4160
RHSA-2021_4162
RHSA-2021_4399
RLSA-2021:4160
RLSA-2021:4162
ROSA-SA-2025-2873
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2021:1490-1
SUSE-SU-2021:1557-1
SUSE-SU-2021:3486-1
SUSE-SU-2021:4015-1
SUSE-SU-2021:4015-2
SUSE-SU-2021:4104-1
SUSE-SU-2021_1490-1
SUSE-SU-2021_1557-1
SUSE-SU-2021_3486-1
SUSE-SU-2021_4015-1
SUSE-SU-2021_4015-2
SUSE-SU-2021_4104-1
USN-5342-1
USN-5342-3
USN-6891-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Python
Red Hat
Rocky Linux
Suse
Ubuntu