CVE-2021-21330
Summary
| CVE | CVE-2021-21330 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-26 03:15:00 UTC |
| Updated | 2023-11-22 17:09:00 UTC |
| Description | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website. It is caused by a bug in the `aiohttp.web_middlewares.normalize_path_middleware` middleware. This security problem has been fixed in 3.7.4. Upgrade your dependency using pip as follows "pip install aiohttp >= 3.7.4". If upgrading is not an option for you, a workaround can be to avoid using `aiohttp.web_middlewares.normalize_path_middleware` in your applications. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: python-aiohttp-3.7.4-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Debian -- Security Information -- DSA-4864-1 python-aiohttp |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 34 Update: python-aiohttp-3.7.4-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Merge branch 'ghsa-v6wp-4m6f-gcjg' into master · aio-libs/aiohttp@2545222 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Open redirect vulnerability in `aiohttp` (`normalize_path_middleware` middleware) · Advisory · aio-libs/aiohttp · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| [SECURITY] Fedora 33 Update: python-aiohttp-3.7.4-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| aiohttp · PyPI |
MISC |
pypi.org |
Product, Third Party Advisory |
| aiohttp/CHANGES.rst at master · aio-libs/aiohttp · GitHub |
MISC |
github.com |
Third Party Advisory |
| aiohttp: Open redirect vulnerability (GLSA 202208-19) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] Fedora 33 Update: python-aiohttp-3.7.4-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 174944 SUSE Enterprise Linux Security Update for python-aiohttp (SUSE-SU-2021:1313-1)
- 180107 Debian Security Update for python-aiohttp (CVE-2021-21330)
- 239895 Red Hat Update for Satellite 6.10 (RHSA-2021:4702)
- 281583 Fedora Security Update for python (FEDORA-2021-673b10ed77)
- 281584 Fedora Security Update for python (FEDORA-2021-902c1b07c9)
- 690101 Free Berkeley Software Distribution (FreeBSD) Security Update for aiohttp (3000acee-c45d-11eb-904f-14dae9d5a9d2)
- 710591 Gentoo Linux aiohttp Open redirect Vulnerability (GLSA 202208-19)
- 980643 Python (pip) Security Update for aiohttp (GHSA-v6wp-4m6f-gcjg)