Updated: 2025-12-28 04:13:23.925255
Description:
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | 0.0 | |
| CVSS Version 3.x | HIGH | 7.4 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| CentOS 7 ELS | python3 | 3.6.8 | 7.4 | HIGH | Released | CLSA-2023:1697739575 | 2023-10-19 21:09:36 | |
| CentOS 8.4 ELS | python3 | 3.6.8 | 7.4 | HIGH | Released | CLSA-2022:1663183291 | 2022-09-14 17:02:43 | |
| CentOS 8.4 ELS | python2 | 2.7.18 | 7.4 | HIGH | Not Vulnerable | 2023-05-18 08:51:07 | ||
| CentOS 8.5 ELS | python2 | 2.7.18 | 7.4 | HIGH | Not Vulnerable | 2023-05-18 08:51:07 | ||
| CentOS 8.5 ELS | python3 | 3.6.8 | 7.4 | HIGH | Released | CLSA-2022:1663184139 | 2022-09-14 17:02:43 | |
| CloudLinux 7 ELS | python3 | 3.6.8 | 7.4 | HIGH | Released | CLSA-2024:1727288754 | 2024-10-07 10:50:30 | |
| Ubuntu 16.04 ELS | python3.5 | 3.5.2 | 7.4 | HIGH | Released | CLSA-2022:1663184406 | 2022-09-14 17:02:43 | |
| Ubuntu 16.04 ELS | python2.7 | 2.7.12 | 7.4 | HIGH | Not Vulnerable | 2022-09-23 08:02:17 | ||
| Ubuntu 18.04 ELS | python3.6 | 3.6.9-1 | 7.4 | HIGH | Released | CLSA-2023:1689259392 | 2023-07-13 11:08:51 |