aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website. It is caused by a bug in the `aiohttp.web_middlewares.normalize_path_middleware` middleware. This security problem has been fixed in 3.7.4. Upgrade your dependency using pip as follows "pip install aiohttp >= 3.7.4". If upgrading is not an option for you, a workaround can be to avoid using `aiohttp.web_middlewares.normalize_path_middleware` in your applications.
CVSS Details
- CVSS 3.1 Base Score: 3.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade python-aiohttp | Mar 1, 2021 | Feb 26, 2021 |
| Freebsd | — | Upgrade py37-aiohttpUpgrade py36-aiohttpUpgrade py39-aiohttpUpgrade py38-aiohttp | Nov 4, 2022 | Jun 3, 2021 |
| Gentoo Linux | — | Upgrade dev-python/aiohttp. | Aug 11, 2022 | Feb 26, 2021 |
| Suse | — | Upgrade python3-aiohttpUpgrade python3-typing_extensionsUpgrade python-aiohttp-doc | Jun 1, 2021 | Feb 26, 2021 |
| Ubuntu | — | Upgrade python3-aiohttp (Ubuntu Pro) | Mar 22, 2023 | Feb 26, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub