Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Mageia: 2024-0235 Moderate: Aiohttp XSS Security Advisory Update

mageia
Calendar Grey June 24, 2024
Dist Mageia Esm H88
Recent updates to the python-aiohttp packages address a critical security vulnerability in Mageia. Explore the details of the cross-site scripting (XSS) issue and recommended fixes
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python

Summary

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.

References

- https://bugs.mageia.org/show_bug.cgi?id=33174

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWEI6NIHZ3G7DURDZVMRK7ZEFC2BTD3U/

- https://www.cve.org/CVERecord?id=CVE-2024-27306

Resolution

SRPMS

- 9/core/python-aiohttp-3.8.3-3.1.mga9

Publication date: 24 Jun 2024
URL: https://advisories.mageia.org/MGASA-2024-0235.html
Type: security
CVE: CVE-2024-27306

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here