NA

CVE-2024-27306

Published: 18/04/2024 Updated: 02/05/2024

Vulnerability Summary

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

Vendor Advisories

Debian Bug report logs - #1070665 python-aiohttp: CVE-2024-27306 Package: src:python-aiohttp; Maintainer for src:python-aiohttp is Debian Python Team <team+python@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 6 May 2024 20:03:02 UTC Severity: important Tags: security, upstream ...