[issue42988] [security] CVE-2021-3426: Information disclosure via pydoc -p: /getfile?key=path allows to read arbitrary file on the filesystem

Ned Deily report at bugs.python.org
Mon Mar 29 11:39:15 EDT 2021


Ned Deily <nad at python.org> added the comment:


New changeset 7c2284f97d140c4e4a85382bfb3a42440be2464d by Miss Islington (bot) in branch '3.7':
bpo-42988: Remove the pydoc getfile feature (GH-25015) (#25066)
https://github.com/python/cpython/commit/7c2284f97d140c4e4a85382bfb3a42440be2464d


----------

_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue42988>
_______________________________________


More information about the Python-bugs-list mailing list