Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-49081
HistoryNov 30, 2023 - 7:15 a.m.

Design/Logic Flaw

2023-11-3007:15:00
PRIOn knowledge base
www.prio-n.com
4
asynchronous http client
python
improper validation
http request modification
http version control

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.8%

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create a new HTTP request if the attacker controls the HTTP version. The vulnerability only occurs if the attacker can control the HTTP version of the request. This issue has been patched in version 3.9.0.

CPENameOperatorVersion
aiohttplt3.9.0

6.8 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

19.8%