Updated python-aiohttp package fixes security vulnerability
Publication date: 30 Mar 2021Modification date: 30 Mar 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-21330
Description
Beast Glatisant and Jelmer Vernooij reported that python-aiohttp is prone to an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website (CVE-2021-21330).
References
SRPMS
8/core
- python-aiohttp-3.7.4-1.mga8