Total vulnerabilities in the database
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Software | From | Fixed in |
---|---|---|
python / python | 3.11.0-alpha2 | 3.11.0-alpha2.x |
python / python | 3.11.0-alpha3 | 3.11.0-alpha3.x |
python / python | 3.11.0-alpha4 | 3.11.0-alpha4.x |
python / python | 3.11.0-alpha5 | 3.11.0-alpha5.x |
python / python | 3.11.0-alpha6 | 3.11.0-alpha6.x |
python / python | 3.11.0-alpha1 | 3.11.0-alpha1.x |
python / python | 3.8.0 | 3.8.14 |
python / python | 3.11.0-beta2 | 3.11.0-beta2.x |
python / python | 3.11.0-beta3 | 3.11.0-beta3.x |
python / python | 3.9.0 | 3.9.14 |
python / python | 3.11.0-alpha7 | 3.11.0-alpha7.x |
python / python | 3.11.0-beta1 | 3.11.0-beta1.x |
python / python | 3.10.0 | 3.10.6 |
python / python | 3.0.0 | 3.7.14 |
fedoraproject / fedora | 35 | 35.x |
fedoraproject / fedora | 36 | 36.x |
fedoraproject / fedora | 37 | 37.x |