From 23e92f1d240aaada2f0d81ec585b76007545f8f4 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Adrian=20Schr=C3=B6ter?= Date: Mon, 23 Dec 2024 20:49:06 +0100 Subject: [PATCH] Adding patchinfo patchinfo.20241220134146182953.90520734224245 --- .../_patchinfo | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) create mode 100644 patchinfo.20241220134146182953.90520734224245/_patchinfo diff --git a/patchinfo.20241220134146182953.90520734224245/_patchinfo b/patchinfo.20241220134146182953.90520734224245/_patchinfo new file mode 100644 index 0000000..7ade207 --- /dev/null +++ b/patchinfo.20241220134146182953.90520734224245/_patchinfo @@ -0,0 +1,22 @@ + + + VUL-0: CVE-2024-27306: python-aiohttp: XSS on index pages for static file handling + VUL-0: CVE-2024-30251: python-aiohttp: infinite loop on specially crafted POST request + VUL-0: CVE-2024-52304: python-aiohttp: vulnerable to request smuggling due to incorrect parsing of chunk extensions + + + + + dgarcia + moderate + security + Security update for python-aiohttp + This update for python-aiohttp fixes the following issues: + +- CVE-2024-27306: Fixed XSS on index pages for static file handling (bsc#1223098) +- CVE-2024-30251: Fixed infinite loop on specially crafted POST request (bsc#1223726) +- CVE-2024-52304: Fixed vulnerable to request smuggling due to incorrect parsing of chunk extensions (bsc#1233447) + + python-aiohttp + +