Bug 2261909 (CVE-2024-23829)
Summary: | CVE-2024-23829 python-aiohttp: http request smuggling | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | ybuenos |
Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
Status: | NEW --- | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | bbuckingham, bcourt, davidn, ehelms, epacific, gtanzill, jcammara, jhardy, jneedle, jobarker, jsherril, lzap, mabashia, mhulan, mminar, nmoumoul, orabin, osapryki, pcreech, rbiba, rchan, simaishi, smcdonal, sskracic, teagle, yguenane, zsadeh |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | aiohttp 3.9.2 | Doc Type: | --- |
Doc Text: |
An HTTP request smuggling vulnerability was found in aiohttp. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets that must trigger error handling to robustly match frame boundaries of proxies in order to protect against the injection of additional requests.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | Type: | --- | |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2261914, 2261918, 2261919, 2261910, 2261911, 2261912, 2261915, 2261916, 2261917, 2266048, 2266049 | ||
Bug Blocks: | 2261913 |
Description
ybuenos
2024-01-30 10:15:36 UTC
Created python-aiohttp tracking bugs for this issue: Affects: epel-all [bug 2261911] Affects: fedora-all [bug 2261910] Created python-gcsfs tracking bugs for this issue: Affects: fedora-38 [bug 2261915] Affects: fedora-39 [bug 2261918] Created python-idna-ssl tracking bugs for this issue: Affects: epel-8 [bug 2261914] Affects: fedora-38 [bug 2261916] Affects: fedora-39 [bug 2261919] Created python-pytelegrambotapi tracking bugs for this issue: Affects: fedora-38 [bug 2261917] This issue has been addressed in the following products: Red Hat Satellite 6.14 for RHEL 8 Via RHSA-2024:1536 https://access.redhat.com/errata/RHSA-2024:1536 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.4 for RHEL 9 Red Hat Ansible Automation Platform 2.4 for RHEL 8 Via RHSA-2024:1640 https://access.redhat.com/errata/RHSA-2024:1640 This issue has been addressed in the following products: RHUI 4 for RHEL 8 Via RHSA-2024:1878 https://access.redhat.com/errata/RHSA-2024:1878 This issue has been addressed in the following products: Red Hat Satellite 6.15 for RHEL 8 Via RHSA-2024:2010 https://access.redhat.com/errata/RHSA-2024:2010 |