Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states Warning: http.server is not recommended for production. It only implements basic security checks.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Python | Python | 3.0.0 (including) | 3.7.14 (excluding) |
Python | Python | 3.8.0 (including) | 3.8.14 (excluding) |
Python | Python | 3.9.0 (including) | 3.9.14 (excluding) |
Python | Python | 3.10.0 (including) | 3.10.6 (excluding) |
Python | Python | 3.11.0-alpha1 (including) | 3.11.0-alpha1 (including) |
Python | Python | 3.11.0-alpha2 (including) | 3.11.0-alpha2 (including) |
Python | Python | 3.11.0-alpha3 (including) | 3.11.0-alpha3 (including) |
Python | Python | 3.11.0-alpha4 (including) | 3.11.0-alpha4 (including) |
Python | Python | 3.11.0-alpha5 (including) | 3.11.0-alpha5 (including) |
Python | Python | 3.11.0-alpha6 (including) | 3.11.0-alpha6 (including) |
Python | Python | 3.11.0-alpha7 (including) | 3.11.0-alpha7 (including) |
Python | Python | 3.11.0-beta1 (including) | 3.11.0-beta1 (including) |
Python | Python | 3.11.0-beta2 (including) | 3.11.0-beta2 (including) |
Python | Python | 3.11.0-beta3 (including) | 3.11.0-beta3 (including) |
Red Hat Enterprise Linux 8 | RedHat | python3-0:3.6.8-48.el8_7.1 | * |
Red Hat Enterprise Linux 8 | RedHat | python38:3.8-8080020221221151857.0d9ba776 | * |
Red Hat Enterprise Linux 8 | RedHat | python38-devel:3.8-8080020221221151857.0d9ba776 | * |
Red Hat Enterprise Linux 8 | RedHat | python39:3.9-8080020221221152015.aed85c85 | * |
Red Hat Enterprise Linux 8 | RedHat | python39-devel:3.9-8080020221221152015.aed85c85 | * |
Red Hat Enterprise Linux 8 | RedHat | python3-0:3.6.8-48.el8_7.1 | * |
Red Hat Enterprise Linux 9 | RedHat | python3.9-0:3.9.14-1.el9 | * |
Red Hat Enterprise Linux 9 | RedHat | python3.9-0:3.9.14-1.el9 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | rh-python38-python-0:3.8.14-1.el7 | * |
Python2.7 | Ubuntu | trusty | * |
Python2.7 | Ubuntu | xenial | * |
Python3.10 | Ubuntu | jammy | * |
Python3.10 | Ubuntu | upstream | * |
Python3.11 | Ubuntu | upstream | * |
Python3.4 | Ubuntu | trusty | * |
Python3.5 | Ubuntu | esm-infra/xenial | * |
Python3.5 | Ubuntu | trusty | * |
Python3.5 | Ubuntu | xenial | * |
Python3.6 | Ubuntu | bionic | * |
Python3.7 | Ubuntu | bionic | * |
Python3.8 | Ubuntu | bionic | * |
Python3.9 | Ubuntu | esm-apps/focal | * |