aiohttp-session
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting aiohttp-sessionpage 1 of 1
- CVE-2018-1000519MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.4.02018-06-26
vulnerable: 0.0.1 ... 2.3.0 (21 versions)
aio-libs aiohttp-session contains a Session Fixation vulnerability in load_session function for RedisStorage (see: https://github.com/aio-libs/aiohttp-session/blob/master/aiohttp_session/redis_storage.py#L42) that can result in Session Hij…
- CVE-2018-1000814MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.7.02018-12-20
vulnerable: 0.0.1 ... 2.6.0 (24 versions)
aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable vi…
Check whether aiohttp-session is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for aiohttp-session CVEs against the assets you own.
Start Free Scan →