CVE-2021-3426 - log back

CVE-2021-3426 edited at 04 Apr 2021 10:37:14
Remote
- Local
+ Remote
References
https://python-security.readthedocs.io/vuln/pydoc-getfile.html
https://bugs.python.org/issue42988
- https://github.com/python/cpython/pull/24285
+ https://github.com/python/cpython/pull/25015
- https://github.com/python/cpython/pull/24337
+ https://github.com/python/cpython/commit/ed753d94856213ae9fc028195f670e66a24e2334
CVE-2021-3426 edited at 11 Mar 2021 08:24:10
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Information disclosure
Description
+ A security issue was found in Python. Running "pydoc -p" allows any user to read arbitrary files on the filesystem by accessing "/getfile?key=path" over HTTP.
References
+ https://python-security.readthedocs.io/vuln/pydoc-getfile.html
+ https://bugs.python.org/issue42988
+ https://github.com/python/cpython/pull/24285
+ https://github.com/python/cpython/pull/24337
Notes
CVE-2021-3426 created at 11 Mar 2021 08:18:11