CVE-2014-4650
Summary
| CVE | CVE-2014-4650 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-20 17:15:00 UTC |
| Updated | 2022-06-27 16:20:00 UTC |
| Description | The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Python | Python | All | All | All | All |
| Application | Python | Python | 2.7.5 | All | All | All |
| Application | Python | Python | 3.3.4 | All | All | All |
| Application | Python | Python | 2.7.5 | All | All | All |
| Application | Python | Python | 3.3.4 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 5.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Application | Redhat | Software Collections | - | All | All | All |
| Application | Redhat | Software Collections | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com | CVE-2014-4650 | REDHAT | access.redhat.com | Third Party Advisory |
| oss-security - Re: CVE ID Request for Python CGIHTTPServer File Disclosure | MISC | openwall.com | Mailing List, Third Party Advisory |
| Issue 21766: CGIHTTPServer File Disclosure - Python tracker | MISC | bugs.python.org | Exploit, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.