VDB
BDU%3A2025-03462
BDU%3A2025-03462
PUBLISHED
CVSS 4 MEDIUM
Уязвимость HTTP-клиента aiohttp, связанная с проблемасм с символической ссылкой при обработке статических маршрутов, содержащих файлы со сжатыми вариантами в классе FileResponse, позволяющая нарушителю скомпрометировать уязвимую систему
Risk Scores
CVSS 2.0
4
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., ООО «Ред Софт», Сообщество свободного программного обеспечения | OpenSUSE Leap, openSUSE Tumbleweed, РЕД ОС (запись в едином реестре российских программ №3751), Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Public Cloud, Suse Linux Enterprise Desktop, aiohttp, SUSE Linux Enterprise Module for Python 3 |
Timeline
- Mar 27, 2025 CVE Published
References
- https://github.com/aio-libs/aiohttp/commit/ce2e9758814527589b10759a20783fb03b98339f url
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jwhx-xcg6-8xhj url
- https://www.suse.com/security/cve/CVE-2024-42367.html url
- https://redos.red-soft.ru/support/secure/ url
- https://github.com/aio-libs/aiohttp/blob/e0ff5246e1d29b7710ab1a2bbc972b48169f1c05/aiohttp/web_fileresponse.py#L177 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://github.com/aio-libs/aiohttp/blob/e0ff5246e1d29b7710ab1a2bbc972b48169f1c05/aiohttp/web_urldispatcher.py#L674 advisory
- https://github.com/aio-libs/aiohttp/pull/8653 advisory