Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 39 2024-e0057e6044 Critical: python-aiohttp XSS Issue

fedora
Calendar Grey May 2, 2024
Dist Fedora Esm H88
Important patch for Python aiohttp in Fedora 39 tackling XSS exploit. Update using 'dnf upgrade' immediately.
Security update for CVE-2024-27306 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.5 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.4

Summary

Python HTTP client/server for asyncio which supports both the client and the

server side of the HTTP protocol, client and server websocket, and webservers

with middlewares and pluggable routing.

Update Information:

Security update for CVE-2024-27306 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.5 https://github.com/aio-libs/aiohttp/releases/tag/v3.9.4

Change Log

* Fri Apr 19 2024 Benjamin A. Beasley - 3.9.5-1 - Update to 3.9.5 (fix RHBZ#2275991, fix CVE-2024-27306)

References


[ 1 ] Bug #2275989 - CVE-2024-27306 aiohttp: XSS on index pages for static file handling https://bugzilla.redhat.com/show_bug.cgi?id=2275989

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-e0057e6044' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-aiohttp
Product: Fedora 39
Version: 3.9.5
Release: 1.fc39
Summary: Python HTTP client/server for asyncio

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here