CVE-2024-27306: aiohttp Cross-site Scripting vulnerability on index pages for static file handling
(updated )
A XSS vulnerability exists on index pages for static file handling.
References
- github.com/advisories/GHSA-7gpw-8wmc-pm8g
- github.com/aio-libs/aiohttp
- github.com/aio-libs/aiohttp/commit/28335525d1eac015a7e7584137678cbb6ff19397
- github.com/aio-libs/aiohttp/pull/8319
- github.com/aio-libs/aiohttp/pull/8319/files
- github.com/aio-libs/aiohttp/security/advisories/GHSA-7gpw-8wmc-pm8g
- lists.debian.org/debian-lts-announce/2025/02/msg00002.html
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2EXRGTN2WG7VZLUZ7WOXU5GQJKCPPHKP
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWEI6NIHZ3G7DURDZVMRK7ZEFC2BTD3U
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZIVBMPEY7WWOFMC3CWXFBRQPFECV4SW3
- nvd.nist.gov/vuln/detail/CVE-2024-27306
Code Behaviors & Features
Detect and mitigate CVE-2024-27306 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →