Логотип exploitDog
bind: "CVE-2024-27306"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2024-27306"

Количество 9

Количество 9

ubuntu логотип

CVE-2024-27306

около 1 года назад

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-27306

около 1 года назад

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-27306

около 1 года назад

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-27306

около 1 года назад

aiohttp is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4396-1

6 месяцев назад

Security update for python-aiohttp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1866-1

около 1 года назад

Security update for python-aiohttp

EPSS: Низкий
github логотип

GHSA-7gpw-8wmc-pm8g

около 1 года назад

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-03458

около 1 года назад

Уязвимость компонента Index Pages HTTP-клиента aiohttp, позволяющая нарушителю оказывать влияние на целостность системы

CVSS3: 6.1
EPSS: Низкий
redos логотип

ROS-20250114-01

5 месяцев назад

Множественные уязвимости python3-aiohttp

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-27306

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

CVSS3: 6.1
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-27306

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

CVSS3: 6.1
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-27306

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

CVSS3: 6.1
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-27306

aiohttp is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 6.1
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4396-1

Security update for python-aiohttp

0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:1866-1

Security update for python-aiohttp

0%
Низкий
около 1 года назад
github логотип
GHSA-7gpw-8wmc-pm8g

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

CVSS3: 6.1
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-03458

Уязвимость компонента Index Pages HTTP-клиента aiohttp, позволяющая нарушителю оказывать влияние на целостность системы

CVSS3: 6.1
0%
Низкий
около 1 года назад
redos логотип
ROS-20250114-01

Множественные уязвимости python3-aiohttp

CVSS3: 7.5
5 месяцев назад

Уязвимостей на страницу