PT-2022-9905 · Python+9 · Python+9

Hamza Avvan

+1

·

Published

2022-08-04

·

Updated

2025-11-14

·

CVE-2021-28861

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Python versions 3.x through 3.10
Description The issue is related to an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path, which may lead to information disclosure. It is noted that this is disputed by a third party because the http.server.html documentation page states that http.server is not recommended for production and only implements basic security checks.
Recommendations For versions 3.x through 3.10, consider disabling the use of http.server for production environments, as recommended by the documentation, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:8353
ALSA-2023:0833
ALSA-2023:2763
ALSA-2023:2764
ALT-PU-2022-2346
ALT-PU-2023-1518
ALT-PU-2024-2598
ALT-PU-2024-3474
AZL-10618
BIT-LIBPYTHON-2021-28861
BIT-PYTHON-2021-28861
BIT-PYTHON-MIN-2021-28861
CESA-2023_0833
CESA-2023_2763
CESA-2023_2764
CVE-2021-28861
DLA-3966-1
DLA-3980-1
MGASA-2022-0359
OESA-2022-1879
OPENSUSE-SU-2022_3473-1
OPENSUSE-SU-2022_3485-1
OPENSUSE-SU-2022_3512-1
OPENSUSE-SU-2022_3544-1
OPENSUSE-SU-2024:12297-1
OPENSUSE-SU-2024:12300-1
OPENSUSE-SU-2024:12301-1
OPENSUSE-SU-2024:12321-1
PSF-2022-5
RHSA-2022:6766
RHSA-2022:8353
RHSA-2022_8353
RHSA-2023:0833
RHSA-2023:2763
RHSA-2023:2764
RHSA-2023_0833
RHSA-2023_2763
RHSA-2023_2764
RLSA-2022:8353
RLSA-2023:0833
ROSA-SA-2025-2676
SUSE-SU-2022:3473-1
SUSE-SU-2022:3483-1
SUSE-SU-2022:3485-1
SUSE-SU-2022:3511-1
SUSE-SU-2022:3511-2
SUSE-SU-2022:3512-1
SUSE-SU-2022:3512-2
SUSE-SU-2022:3544-1
SUSE-SU-2022:3553-1
SUSE-SU-2022:3593-1
SUSE-SU-2022:3940-1
SUSE-SU-2022_3483-1
SUSE-SU-2022_3511-1
SUSE-SU-2022_3511-2
SUSE-SU-2022_3512-1
SUSE-SU-2022_3512-2
SUSE-SU-2022_3544-1
SUSE-SU-2022_3553-1
SUSE-SU-2022_3593-1
SUSE-SU-2022_3940-1
USN-5629-1
USN-5888-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Python
Red Hat
Rocky Linux
Suse
Ubuntu