Skip to content

[security] CVE-2021-28861: http.server: Open Redirection if the URL path starts with // #87389

Closed
@hamzaavvan

Description

@hamzaavvan
BPO 43223
Nosy @pfmoore, @vstinner, @tiran, @tjguk, @ned-deily, @ambv, @zware, @zooba, @hamzaavvan
PRs
  • bpo-43223: [SECURITY] Patched Open Redirection In SimpleHTTPServer Module #24848
  • Files
  • Capture.PNG
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = None
    created_at = <Date 2021-02-14.11:42:36.898>
    labels = ['type-security', 'deferred-blocker', '3.8', '3.9', '3.10', '3.11', '3.7', 'library']
    title = '[security] http.server: Open Redirection if the URL path starts with //'
    updated_at = <Date 2021-05-23.08:10:57.234>
    user = 'https://github.com/hamzaavvan'

    bugs.python.org fields:

    activity = <Date 2021-05-23.08:10:57.234>
    actor = 'hamzaavvan'
    assignee = 'none'
    closed = False
    closed_date = None
    closer = None
    components = ['Library (Lib)']
    creation = <Date 2021-02-14.11:42:36.898>
    creator = 'hamzaavvan'
    dependencies = []
    files = ['49808']
    hgrepos = ['404']
    issue_num = 43223
    keywords = ['patch']
    message_count = 5.0
    messages = ['386945', '387193', '387284', '390047', '394193']
    nosy_count = 9.0
    nosy_names = ['paul.moore', 'vstinner', 'christian.heimes', 'tim.golden', 'ned.deily', 'lukasz.langa', 'zach.ware', 'steve.dower', 'hamzaavvan']
    pr_nums = ['24848']
    priority = 'deferred blocker'
    resolution = None
    stage = 'patch review'
    status = 'open'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue43223'
    versions = ['Python 3.6', 'Python 3.7', 'Python 3.8', 'Python 3.9', 'Python 3.10', 'Python 3.11']

    Linked PRs

    Metadata

    Metadata

    Assignees

    Labels

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions