UBUNTU-CVE-2021-28861

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2021-28861
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-28861.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-28861
Related
Published
2022-08-23T01:15:00Z
Modified
2022-08-23T01:15:00Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

* DISPUTED * Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

References

Affected packages

Ubuntu:Pro:16.04:LTS / python3.5

Package

Name
python3.5
Purl
pkg:deb/ubuntu/python3.5@3.5.2-2ubuntu0~16.04.13+esm5?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.2-2ubuntu0~16.04.13+esm5

Affected versions

3.*

3.5.0-3
3.5.0-3ubuntu1
3.5.1~rc1-2ubuntu1
3.5.1-1
3.5.1-2
3.5.1-3
3.5.1-5
3.5.1-6ubuntu1
3.5.1-6ubuntu2
3.5.1-9ubuntu1
3.5.1-10
3.5.2-2~16.01
3.5.2-2~16.04
3.5.2-2ubuntu0~16.04.1
3.5.2-2ubuntu0~16.04.2
3.5.2-2ubuntu0~16.04.3
3.5.2-2ubuntu0~16.04.4
3.5.2-2ubuntu0~16.04.5
3.5.2-2ubuntu0~16.04.8
3.5.2-2ubuntu0~16.04.9
3.5.2-2ubuntu0~16.04.10
3.5.2-2ubuntu0~16.04.11
3.5.2-2ubuntu0~16.04.12
3.5.2-2ubuntu0~16.04.13
3.5.2-2ubuntu0~16.04.13+esm1
3.5.2-2ubuntu0~16.04.13+esm2
3.5.2-2ubuntu0~16.04.13+esm3

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "python3.5-dev": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5-minimal-dbgsym": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5-dbgsym": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5-dbg": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5-minimal": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5-stdlib": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5": "3.5.2-2ubuntu0~16.04.13+esm5",
            "python3.5-minimal": "3.5.2-2ubuntu0~16.04.13+esm5",
            "idle-python3.5": "3.5.2-2ubuntu0~16.04.13+esm5",
            "python3.5-venv": "3.5.2-2ubuntu0~16.04.13+esm5",
            "python3.5-examples": "3.5.2-2ubuntu0~16.04.13+esm5",
            "python3.5": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5-dev": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5-stdlib-dbgsym": "3.5.2-2ubuntu0~16.04.13+esm5",
            "python3.5-dbg": "3.5.2-2ubuntu0~16.04.13+esm5",
            "python3.5-doc": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5-testsuite": "3.5.2-2ubuntu0~16.04.13+esm5",
            "libpython3.5-dev-dbgsym": "3.5.2-2ubuntu0~16.04.13+esm5"
        }
    ],
    "priority_reason": "Works as documented, and disputed as being a security issue"
}

Ubuntu:Pro:20.04:LTS / python3.9

Package

Name
python3.9
Purl
pkg:deb/ubuntu/python3.9@3.9.5-3ubuntu0~20.04.1+esm1?arch=src?distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.5-3ubuntu0~20.04.1+esm1

Affected versions

3.*

3.9.0~rc1-1~20.04
3.9.0-5~20.04
3.9.5-3~20.04.1
3.9.5-3ubuntu0~20.04.1

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "libpython3.9": "3.9.5-3ubuntu0~20.04.1+esm1",
            "libpython3.9-stdlib": "3.9.5-3ubuntu0~20.04.1+esm1",
            "python3.9-dbg": "3.9.5-3ubuntu0~20.04.1+esm1",
            "python3.9-venv": "3.9.5-3ubuntu0~20.04.1+esm1",
            "libpython3.9-dbg": "3.9.5-3ubuntu0~20.04.1+esm1",
            "idle-python3.9": "3.9.5-3ubuntu0~20.04.1+esm1",
            "python3.9": "3.9.5-3ubuntu0~20.04.1+esm1",
            "libpython3.9-minimal": "3.9.5-3ubuntu0~20.04.1+esm1",
            "python3.9-dev": "3.9.5-3ubuntu0~20.04.1+esm1",
            "python3.9-examples": "3.9.5-3ubuntu0~20.04.1+esm1",
            "libpython3.9-dev": "3.9.5-3ubuntu0~20.04.1+esm1",
            "libpython3.9-testsuite": "3.9.5-3ubuntu0~20.04.1+esm1",
            "python3.9-doc": "3.9.5-3ubuntu0~20.04.1+esm1",
            "python3.9-full": "3.9.5-3ubuntu0~20.04.1+esm1",
            "python3.9-minimal": "3.9.5-3ubuntu0~20.04.1+esm1"
        }
    ],
    "priority_reason": "Works as documented, and disputed as being a security issue"
}

Ubuntu:22.04:LTS / python3.10

Package

Name
python3.10
Purl
pkg:deb/ubuntu/python3.10@3.10.6-1~22.04.1?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.10.6-1~22.04.1

Affected versions

3.*

3.10.0-2
3.10.0-3
3.10.0-4
3.10.0-5
3.10.0-5build1
3.10.1-1
3.10.1-2
3.10.2-1
3.10.2-5
3.10.2-7
3.10.3-1
3.10.4-3
3.10.4-3ubuntu0.1
3.10.6-1~22.04

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "libpython3.10": "3.10.6-1~22.04.1",
            "python3.10": "3.10.6-1~22.04.1",
            "libpython3.10-stdlib": "3.10.6-1~22.04.1",
            "python3.10-examples": "3.10.6-1~22.04.1",
            "libpython3.10-dev": "3.10.6-1~22.04.1",
            "python3.10-dev": "3.10.6-1~22.04.1",
            "python3.10-doc": "3.10.6-1~22.04.1",
            "python3.10-nopie": "3.10.6-1~22.04.1",
            "libpython3.10-testsuite": "3.10.6-1~22.04.1",
            "python3.10-venv": "3.10.6-1~22.04.1",
            "libpython3.10-minimal": "3.10.6-1~22.04.1",
            "python3.10-full": "3.10.6-1~22.04.1",
            "python3.10-dbg": "3.10.6-1~22.04.1",
            "idle-python3.10": "3.10.6-1~22.04.1",
            "python3.10-minimal": "3.10.6-1~22.04.1",
            "libpython3.10-dbg": "3.10.6-1~22.04.1"
        }
    ],
    "priority_reason": "Works as documented, and disputed as being a security issue"
}

Ubuntu:22.04:LTS / python3.11

Package

Name
python3.11
Purl
pkg:deb/ubuntu/python3.11@3.11.0~rc1-1~22.04?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.11.0~rc1-1~22.04

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "low",
    "binaries": [
        {
            "python3.11-minimal": "3.11.0~rc1-1~22.04",
            "python3.11-examples": "3.11.0~rc1-1~22.04",
            "python3.11": "3.11.0~rc1-1~22.04",
            "idle-python3.11": "3.11.0~rc1-1~22.04",
            "libpython3.11-dev": "3.11.0~rc1-1~22.04",
            "python3.11-dbg": "3.11.0~rc1-1~22.04",
            "libpython3.11-dbg": "3.11.0~rc1-1~22.04",
            "libpython3.11": "3.11.0~rc1-1~22.04",
            "libpython3.11-testsuite": "3.11.0~rc1-1~22.04",
            "libpython3.11-minimal": "3.11.0~rc1-1~22.04",
            "python3.11-dev": "3.11.0~rc1-1~22.04",
            "python3.11-full": "3.11.0~rc1-1~22.04",
            "python3.11-venv": "3.11.0~rc1-1~22.04",
            "libpython3.11-stdlib": "3.11.0~rc1-1~22.04",
            "python3.11-doc": "3.11.0~rc1-1~22.04",
            "python3.11-nopie": "3.11.0~rc1-1~22.04"
        }
    ],
    "priority_reason": "Works as documented, and disputed as being a security issue"
}