Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2024-27306
Description:aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected. Other users can disable `show_index` if unable to upgrade.
Test IDs: 1.3.6.1.4.1.25623.1.1.10.2024.0235   1.3.6.1.4.1.25623.1.0.856870   1.3.6.1.4.1.25623.1.0.886556   1.3.6.1.4.1.25623.1.0.886662   1.3.6.1.4.1.25623.1.0.886759   1.3.6.1.4.1.25623.1.0.886743   1.3.6.1.4.1.25623.1.0.856370  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2024-27306
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZIVBMPEY7WWOFMC3CWXFBRQPFECV4SW3/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2EXRGTN2WG7VZLUZ7WOXU5GQJKCPPHKP/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWEI6NIHZ3G7DURDZVMRK7ZEFC2BTD3U/
https://github.com/aio-libs/aiohttp/commit/28335525d1eac015a7e7584137678cbb6ff19397
https://github.com/aio-libs/aiohttp/commit/28335525d1eac015a7e7584137678cbb6ff19397
https://github.com/aio-libs/aiohttp/pull/8319
https://github.com/aio-libs/aiohttp/pull/8319
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-7gpw-8wmc-pm8g
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-7gpw-8wmc-pm8g




© 1998-2025 E-Soft Inc. All rights reserved.