[issue42988] [security] CVE-2021-3426: Information disclosure via pydoc -p: /getfile?key=path allows to read arbitrary file on the filesystem
STINNER Victor
report at bugs.python.org
Mon Mar 29 08:41:00 EDT 2021
STINNER Victor <vstinner at python.org> added the comment:
New changeset 9b999479c0022edfc9835a8a1f06e046f3881048 by Victor Stinner in branch 'master':
bpo-42988: Remove the pydoc getfile feature (GH-25015)
https://github.com/python/cpython/commit/9b999479c0022edfc9835a8a1f06e046f3881048
----------
_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue42988>
_______________________________________
More information about the Python-bugs-list
mailing list