Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-27306
HistoryApr 18, 2024 - 12:00 a.m.

CVE-2024-27306

2024-04-1800:00:00
ubuntu.com
ubuntu.com
8
aiohttp
http client/server
asyncio
python
xss vulnerability
static file handling
reverse proxy server
nginx
show_index
upgrade
unix

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%

aiohttp is an asynchronous HTTP client/server framework for asyncio and
Python. A XSS vulnerability exists on index pages for static file handling.
This vulnerability is fixed in 3.9.4. We have always recommended using a
reverse proxy server (e.g. nginx) for serving static files. Users following
the recommendation are unaffected. Other users can disable show_index if
unable to upgrade.

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.3 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.3%