Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

github логотип

GHSA-5h86-8mv2-jq9f

больше 2 лет назад

aiohttp is vulnerable to directory traversal

CVSS3: 5.9
EPSS: Высокий
ubuntu логотип

CVE-2024-23334

больше 2 лет назад

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

CVSS3: 5.9
EPSS: Высокий
redhat логотип

CVE-2024-23334

больше 2 лет назад

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

CVSS3: 5.9
EPSS: Высокий
nvd логотип

CVE-2024-23334

больше 2 лет назад

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

CVSS3: 5.9
EPSS: Высокий
msrc логотип

CVE-2024-23334

12 месяцев назад

aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal

EPSS: Высокий
debian логотип

CVE-2024-23334

больше 2 лет назад

aiohttp is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.9
EPSS: Высокий
fstec логотип

BDU:2024-00995

больше 2 лет назад

Уязвимость HTTP-клиента aiohttp, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2024:0577-1

больше 2 лет назад

Security update for python-aiohttp, python-time-machine

EPSS: Низкий
redos логотип

ROS-20240423-07

больше 2 лет назад

Множественные уязвимости python3-aiohttp

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5h86-8mv2-jq9f

aiohttp is vulnerable to directory traversal

CVSS3: 5.9
77%
Высокий
больше 2 лет назад
ubuntu логотип
CVE-2024-23334

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

CVSS3: 5.9
77%
Высокий
больше 2 лет назад
redhat логотип
CVE-2024-23334

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

CVSS3: 5.9
77%
Высокий
больше 2 лет назад
nvd логотип
CVE-2024-23334

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

CVSS3: 5.9
77%
Высокий
больше 2 лет назад
msrc логотип
CVE-2024-23334

aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal

77%
Высокий
12 месяцев назад
debian логотип
CVE-2024-23334

aiohttp is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.9
77%
Высокий
больше 2 лет назад
fstec логотип
BDU:2024-00995

Уязвимость HTTP-клиента aiohttp, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
77%
Высокий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0577-1

Security update for python-aiohttp, python-time-machine

больше 2 лет назад
redos логотип
ROS-20240423-07

Множественные уязвимости python3-aiohttp

CVSS3: 7.5
больше 2 лет назад

Уязвимостей на страницу