gh-87389: Fix an open redirection vulnerability in http.server. by gpshead · Pull Request #93879 · python/cpython · GitHub

github.com

Tin mới

gpshead:security-gh87389

GitHub CopilotWrite better code with AI

GitHub Copilot appDirect agents from issue to merge

ActionsAutomate any workflow

CodespacesInstant dev environments

IssuesPlan and track work

Code ReviewManage code changes

Code QualityEnforce quality at merge

GitHub Advanced SecurityFind and fix vulnerabilities

Code securitySecure your code as you build

Secret protectionStop leaks before they start

View all use cases

Financial services

View all industries

Software Development

GitHub SponsorsFund open source developers

Copilot for BusinessEnterprise-grade AI features

Premium SupportEnterprise-grade 24/7 support

Pull requests 2.6k

Security and quality 0

: Fix an open redirection vulnerability in http.server.

awaiting core review

awaiting core review

bpo-43223: [SECURITY] Patched Open Redirection In SimpleHTTPServer Module #24848

needs backport to 3.7

needs backport to 3.7

needs backport to 3.10

needs backport to 3.10

needs backport to 3.11

needs backport to 3.11

A more defensive assert within the test.

[security] CVE-2021-28861: http.server: Open Redirection if the URL path starts with // #87389

Fix wording in some comments.

Add an explanatory comment in the test.

View reviewed changes

Learn more about hiding disruptive comments

The reason will be displayed to describe this comment to others. Learn more.

Address vstinner comments on the test.

View reviewed changes

: Fix an open redirection vulnerability in http.server. (

: Fix an open redirection vulnerability in http.server. (

: Fix an open redirection vulnerability in http.server. (

: Fix an open redirection vulnerability in http.server. (

Revert 30935 defer bpo45162 to 312 (

emscripten-core/emscripten#17269

https://github.com/python/cpython/issue/89336

test_httpretty_should_handle_paths_starting_with_two_slashes needs update gabrielfalcao/HTTPretty#457

Patch Python3 to fix CVE-2021-28861 microsoft/azurelinux#3673

00386: CVE-2021-28861 Upstream: https://github.com/python/cpython/pull/93879 Tracking bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=2120642

[sancov] fix coverage-report-server cannot display coverage detail

https://github.com/python/cpython/security/advisories/GHSA-cmpp-8h97-9wv9

@gpshead , Thanks. Created https://github.com/python/cpython/security/advisories/GHSA-cmpp-8h97-9wv9