vulnerability
Rocky Linux: CVE-2021-28861: python39-3.9-and-python39-devel-3.9 (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:C/I:N/A:N) | Aug 23, 2022 | Apr 18, 2024 | Dec 29, 2025 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:C/I:N/A:N)
Published
Aug 23, 2022
Added
Apr 18, 2024
Modified
Dec 29, 2025
Description
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Solutions
rocky-upgrade-cython-debugsourcerocky-upgrade-numpy-debugsourcerocky-upgrade-platform-pythonrocky-upgrade-platform-python-debugrocky-upgrade-platform-python-develrocky-upgrade-python-cffi-debugsourcerocky-upgrade-python-cryptography-debugsourcerocky-upgrade-python-lxml-debugsourcerocky-upgrade-python-markupsafe-debugsourcerocky-upgrade-python-psutil-debugsourcerocky-upgrade-python-psycopg2-debugsourcerocky-upgrade-python3rocky-upgrade-python3-debugrocky-upgrade-python3-debuginforocky-upgrade-python3-debugsourcerocky-upgrade-python3-develrocky-upgrade-python3-idlerocky-upgrade-python3-libsrocky-upgrade-python3-testrocky-upgrade-python3-tkinterrocky-upgrade-python3.9-debuginforocky-upgrade-python38-cffirocky-upgrade-python38-cffi-debuginforocky-upgrade-python38-cryptographyrocky-upgrade-python38-cryptography-debuginforocky-upgrade-python38-cythonrocky-upgrade-python38-cython-debuginforocky-upgrade-python38-lxmlrocky-upgrade-python38-lxml-debuginforocky-upgrade-python38-markupsaferocky-upgrade-python38-markupsafe-debuginforocky-upgrade-python38-psutilrocky-upgrade-python38-psutil-debuginforocky-upgrade-python38-psycopg2rocky-upgrade-python38-psycopg2-debuginforocky-upgrade-python38-psycopg2-docrocky-upgrade-python38-psycopg2-testsrocky-upgrade-python38-pyyamlrocky-upgrade-python38-pyyaml-debuginforocky-upgrade-python39-cffirocky-upgrade-python39-cffi-debuginforocky-upgrade-python39-cythonrocky-upgrade-python39-cython-debuginforocky-upgrade-python39-lxmlrocky-upgrade-python39-lxml-debuginforocky-upgrade-python39-numpyrocky-upgrade-python39-numpy-debuginforocky-upgrade-python39-numpy-f2pyrocky-upgrade-python39-psutilrocky-upgrade-python39-psutil-debuginforocky-upgrade-python39-pybind11rocky-upgrade-python39-pybind11-develrocky-upgrade-python39-pyyamlrocky-upgrade-python39-pyyaml-debuginforocky-upgrade-pyyaml-debugsource
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.