vulnerability

Rocky Linux: CVE-2021-28861: python3 (Multiple Advisories)

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:C/I:N/A:N)
Published
Aug 23, 2022
Added
Apr 18, 2024
Modified
Aug 13, 2025

Description

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

Solutions

rocky-upgrade-platform-pythonrocky-upgrade-platform-python-debugrocky-upgrade-platform-python-develrocky-upgrade-python3rocky-upgrade-python3-debugrocky-upgrade-python3-debuginforocky-upgrade-python3-debugsourcerocky-upgrade-python3-develrocky-upgrade-python3-idlerocky-upgrade-python3-libsrocky-upgrade-python3-testrocky-upgrade-python3-tkinterrocky-upgrade-python3.9-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.