QID 995940
Date Published: 2023-11-16
QID 995940: Python (Pip) Security Update for aiohttp (GHSA-xx9p-xxvh-7g8j)
Aiohttp has a security vulnerability regarding the inconsistent interpretation of the http protocol. As we know that HTTP/1.1 is persistent, if we have both Content-Length(CL) and Transfer-Encoding(TE) it can lead to incorrect interpretation of two entities that parse the HTTP and we can poison other sockets with this incorrect interpretation.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xx9p-xxvh-7g8j for updates and patch information.
Vendor References
- GHSA-xx9p-xxvh-7g8j -
github.com/advisories/GHSA-xx9p-xxvh-7g8j
CVEs related to QID 995940
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xx9p-xxvh-7g8j | aiohttp |
|