bpo-43223: [SECURITY] Patched Open Redirection In SimpleHTTPServer Module by hamzaavvan · Pull Request #24848 · python/cpython · GitHub

github.com

Tin mới

hamzaavvan:fix-issue-43223

GitHub CopilotWrite better code with AI

GitHub Copilot appDirect agents from issue to merge

ActionsAutomate any workflow

CodespacesInstant dev environments

IssuesPlan and track work

Code ReviewManage code changes

Code QualityEnforce quality at merge

GitHub Advanced SecurityFind and fix vulnerabilities

Code securitySecure your code as you build

Secret protectionStop leaks before they start

View all use cases

Financial services

View all industries

Software Development

GitHub SponsorsFund open source developers

Copilot for BusinessEnterprise-grade AI features

Premium SupportEnterprise-grade 24/7 support

Pull requests 2.6k

Security and quality 0

Lib/http/server.py

Due to no protection against multiple (/) at the beginning of a url an attacker could achieve an open redirection by crafting a malformed URI followed by an existing directory.

View reviewed changes

Learn more about hiding disruptive comments

The reason will be displayed to describe this comment to others. Learn more.

github-actions Bot commented Apr 18, 2021

github-actions Bot commented Apr 18, 2021

This PR is stale because it has been open for 30 days with no activity.

bpo-43223: Fix Open Redirection In http.server module

View reviewed changes

https://github.com/notifications/unsubscribe-auth/ACNY3RNMO7QIH6RKTIMDD53VEAXYXANCNFSM4ZEGXF4Q

[security] CVE-2021-28861: http.server: Open Redirection if the URL path starts with // #87389

gh-87389: Fix an open redirection vulnerability in http.server. #93879

rustpython-pylib-0.4.0.crate: 28 vulnerabilities (highest severity is: 9.8) IBM/prompt-declaration-language#1198