FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-16 06:42:40 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
3000acee-c45d-11eb-904f-14dae9d5a9d2aiohttp -- open redirect vulnerability

Sviatoslav Sydorenko reports:

Open redirect vulnerability — a maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website.

It is caused by a bug in the aiohttp.web_middlewares.normalize_path_middleware middleware.


Discovery 2021-02-25
Entry 2021-06-03
Modified 2021-06-23
py36-aiohttp
py37-aiohttp
py38-aiohttp
py39-aiohttp
le 3.7.3

CVE-2021-21330
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-v6wp-4m6f-gcjg
https://nvd.nist.gov/vuln/detail/CVE-2021-21330