Lucene search

K
osvGoogleOSV:GHSA-V6WP-4M6F-GCJG
HistoryFeb 26, 2021 - 2:11 a.m.

`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)

2021-02-2602:11:57
Google
osv.dev
19

6.2 Medium

AI Score

Confidence

High

0.01 Low

EPSS

Percentile

83.9%

Impact

Open redirect vulnerability β€” a maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website.

It is caused by a bug in the aiohttp.web_middlewares.normalize_path_middleware middleware.

Patches

This security problem has been fixed in v3.7.4. Upgrade your dependency as follows:
pip install aiohttp >= 3.7.4

Workarounds

If upgrading is not an option for you, a workaround can be to avoid using aiohttp.web_middlewares.normalize_path_middleware in your applications.

References

For more information

If you have any questions or comments about this advisory:

Credit: Jelmer VernooΔ³ and Beast Glatisant.