Логотип exploitDog
bind:"BDU:2024-04194" OR bind:"CVE-2024-30251"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2024-04194" OR bind:"CVE-2024-30251"

Количество 10

Количество 10

fstec логотип

BDU:2024-04194

почти 2 года назад

Уязвимость HTTP-клиента aiohttp, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250114-01

около 1 года назад

Множественные уязвимости python3-aiohttp

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-30251

почти 2 года назад

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-30251

почти 2 года назад

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-30251

почти 2 года назад

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-30251

5 месяцев назад

Denial of service when trying to parse malformed POST requests in aiohttp

EPSS: Низкий
debian логотип

CVE-2024-30251

почти 2 года назад

aiohttp is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4328-1

около 1 года назад

Security update for python-aiohttp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4327-1

около 1 года назад

Security update for python-aiohttp

EPSS: Низкий
github логотип

GHSA-5m98-qgg9-wh84

почти 2 года назад

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-04194

Уязвимость HTTP-клиента aiohttp, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
почти 2 года назад
redos логотип
ROS-20250114-01

Множественные уязвимости python3-aiohttp

CVSS3: 7.5
около 1 года назад
ubuntu логотип
CVE-2024-30251

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-30251

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-30251

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests. An attacker can stop the application from serving requests after sending a single request. This issue has been addressed in version 3.9.4. Users are advised to upgrade. Users unable to upgrade may manually apply a patch to their systems. Please see the linked GHSA for instructions.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
msrc логотип
CVE-2024-30251

Denial of service when trying to parse malformed POST requests in aiohttp

0%
Низкий
5 месяцев назад
debian логотип
CVE-2024-30251

aiohttp is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 7.5
0%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:4328-1

Security update for python-aiohttp

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:4327-1

Security update for python-aiohttp

0%
Низкий
около 1 года назад
github логотип
GHSA-5m98-qgg9-wh84

aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests

CVSS3: 7.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу