Описание
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable show_index if unable to upgrade.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 3.11.16-1 |
| esm-apps/bionic | released | 3.0.1-1ubuntu0.1~esm5 |
| esm-apps/focal | released | 3.6.2-1ubuntu1+esm4 |
| esm-apps/jammy | released | 3.8.1-4ubuntu0.2+esm1 |
| esm-apps/noble | released | 3.9.1-1ubuntu0.1+esm1 |
| esm-apps/xenial | not-affected | code not present |
| focal | ignored | end of standard support, was needs-triage |
| jammy | needed | |
| mantic | ignored | end of life, was needs-triage |
| noble | needed |
Показывать по
Ссылки на источники
6.1 Medium
CVSS3
Связанные уязвимости
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.
aiohttp is an asynchronous HTTP client/server framework for asyncio an ...
6.1 Medium
CVSS3