The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python2.7 | Jul 30, 2024 | Feb 20, 2020 |
| Oracle_linux | — | Upgrade python-toolsUpgrade python27-tkinterUpgrade python27Upgrade python27-python-toolsUpgrade tkinterUpgrade python27-python-develUpgrade pythonUpgrade python-testUpgrade python27-scldevelUpgrade python27-pythonUpgrade python27-runtimeUpgrade python27-python-libsUpgrade python27-python-simplejsonUpgrade python27-python-wheelUpgrade python27-python-testUpgrade python-debugUpgrade python-libsUpgrade python-develUpgrade python27-python-debugUpgrade python27-python-setuptoolsUpgrade python27-python-pip | Oct 16, 2024 | Feb 20, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 20, 2020 |
| Suse | — | Upgrade python39Upgrade python3-idleUpgrade python39-dbmUpgrade python3-develUpgrade python3Upgrade python-develUpgrade python-idleUpgrade libpython2_6-1_0-32bitUpgrade python39-tkUpgrade python-docUpgrade python-base-x86Upgrade libpython3_6m1_0-32bitUpgrade python39-develUpgrade libpython3_9-1_0Upgrade libpython2_7-1_0-32bitUpgrade python-demoUpgrade python3-baseUpgrade python39-idleUpgrade libpython3_4m1_0Upgrade python39-toolsUpgrade python3-32bitUpgrade libpython3_4m1_0-32bitUpgrade python-cursesUpgrade python-doc-pdfUpgrade python-xmlUpgrade python39-cursesUpgrade python39-baseUpgrade pythonUpgrade libpython2_7-1_0Upgrade python36Upgrade python-32bitUpgrade libpython3_6m1_0Upgrade python-x86Upgrade python3-tkUpgrade python3-base-32bitUpgrade python-gdbmUpgrade python-tkUpgrade libpython2_6-1_0-x86Upgrade python3-cursesUpgrade python36-baseUpgrade python3-testsuiteUpgrade python3-toolsUpgrade python-base-32bitUpgrade python3-dbmUpgrade python-baseUpgrade libpython2_6-1_0 | Dec 18, 2015 | Jun 25, 2015 |
| Ubuntu | — | Upgrade python3.2Upgrade python3.4Upgrade python3.4-minimalUpgrade python2.7-minimalUpgrade python2.7Upgrade python3.2-minimal | Nov 8, 2024 | Feb 20, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub