Related Vulnerabilities: CVE-2021-3426  

A security issue was found in Python. Running "pydoc -p" allows any user to read arbitrary files on the filesystem by accessing "/getfile?key=path" over HTTP.

Severity Medium

Remote No

Type Information disclosure

Description

A security issue was found in Python. Running "pydoc -p" allows any user to read arbitrary files on the filesystem by accessing "/getfile?key=path" over HTTP.

AVG-1675 python 3.9.2-1 Medium Vulnerable

https://python-security.readthedocs.io/vuln/pydoc-getfile.html
https://bugs.python.org/issue42988
https://github.com/python/cpython/pull/24285
https://github.com/python/cpython/pull/24337