Описание
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable show_index
if unable to upgrade.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 3.11.16-1 |
esm-apps/bionic | released | 3.0.1-1ubuntu0.1~esm5 |
esm-apps/focal | released | 3.6.2-1ubuntu1+esm4 |
esm-apps/jammy | released | 3.8.1-4ubuntu0.2+esm1 |
esm-apps/noble | released | 3.9.1-1ubuntu0.1+esm1 |
esm-apps/xenial | not-affected | code not present |
focal | ignored | end of standard support, was needs-triage |
jammy | needed | |
mantic | ignored | end of life, was needs-triage |
noble | needed |
Показывать по
Ссылки на источники
EPSS
6.1 Medium
CVSS3
Связанные уязвимости
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.
aiohttp is an asynchronous HTTP client/server framework for asyncio an ...
EPSS
6.1 Medium
CVSS3