An open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. References: https://bugs.python.org/issue43223
Created mingw-python3 tracking bugs for this issue: Affects: fedora-all [bug 2120645] Created python34 tracking bugs for this issue: Affects: epel-7 [bug 2120644]
Created pypy3.7 tracking bugs for this issue: Affects: fedora-all [bug 2120787] Created pypy3.8 tracking bugs for this issue: Affects: fedora-all [bug 2120788] Created pypy3.9 tracking bugs for this issue: Affects: fedora-all [bug 2120789] Created python3.6 tracking bugs for this issue: Affects: fedora-all [bug 2120785] Created python3.7 tracking bugs for this issue: Affects: fedora-all [bug 2120784] Created python3.8 tracking bugs for this issue: Affects: fedora-all [bug 2120783] Created python3.9 tracking bugs for this issue: Affects: fedora-all [bug 2120786]
Upstream fix: https://github.com/python/cpython/pull/93879
Created python3.10 tracking bugs for this issue: Affects: fedora-all [bug 2121034] Created python3.11 tracking bugs for this issue: Affects: fedora-all [bug 2121035]
The upstream fix is merged upstream for Python 3.7+ and released in 3.7.14, 3.8.14, 3.9.14, 3.10.6 and 3.11.0b4.
This issue has been addressed in the following products: Red Hat Software Collections for Red Hat Enterprise Linux 7 Via RHSA-2022:6766 https://access.redhat.com/errata/RHSA-2022:6766
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2022:8353 https://access.redhat.com/errata/RHSA-2022:8353
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:0833 https://access.redhat.com/errata/RHSA-2023:0833
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:2763 https://access.redhat.com/errata/RHSA-2023:2763
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:2764 https://access.redhat.com/errata/RHSA-2023:2764
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-28861