vulnerability

FreeBSD: VID-f671c282-95ef-11eb-9c34-080027f515ea (CVE-2021-3426): python -- Information disclosure via pydoc -p: /getfile?key=path allows to read arbitrary file on the filesystem

Severity
3
CVSS
(AV:A/AC:L/Au:S/C:P/I:N/A:N)
Published
Apr 10, 2021
Added
Nov 4, 2022
Modified
Dec 10, 2025

Description

David Schwörer reports: Remove the getfile feature of the pydoc module which could be abused to read arbitrary files on the disk (directory traversal vulnerability). Moreover, even source code of Python modules can contain sensitive data like passwords.

Solutions

freebsd-upgrade-package-python38freebsd-upgrade-package-python39
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.