QID 981101
QID 981101: Python (pip) Security Update for aiohttp-session (GHSA-fpwp-69xv-c67f)
The pypi package aiohttp-session before 2.4.0 contained a Session Fixation vulnerability in load_session function for RedisStorage that can result in Session Hijacking. This attack appear to be exploitable via Any method that allows setting session cookies (?session=<>, or meta tags or script tags with Set-Cookie).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-fpwp-69xv-c67f for updates pertaining to this vulnerability.
Vendor References
- GHSA-fpwp-69xv-c67f -
github.com/advisories/GHSA-fpwp-69xv-c67f
CVEs related to QID 981101
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fpwp-69xv-c67f | aiohttp-session |
|