QID 980977
QID 980977: Python (pip) Security Update for aiohttp-session (GHSA-mr4x-c4v9-x729)
aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mr4x-c4v9-x729 for updates pertaining to this vulnerability.
Vendor References
- GHSA-mr4x-c4v9-x729 -
github.com/advisories/GHSA-mr4x-c4v9-x729
CVEs related to QID 980977
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mr4x-c4v9-x729 | aiohttp-session |
|