Logo
vulnerabilityCVE-2024-27306
Name
CVE-2024-27306
Source
NVD ( link)Debian ( link)
Description
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python3-aiohttp
Patched

Vulnerability Ratings#


6.1
CVSSv31
NaN
other

Others affected component#


Name
Project
Project Version
Version
Status
yocto
scarthgap
3.9.5
Not Affected

Resolved with patches#


python3-aiohttp (yocto:kirkstone)

#
Title
Author
Resolve
1
Escape filenames and paths in HTML when generating index
Sam Bull <git@sambull.org>
CVE-2024-27306