Advisories ยป MGASA-2021-0161

Updated python-aiohttp package fixes security vulnerability

Publication date: 30 Mar 2021
Modification date: 30 Mar 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-21330

Description

Beast Glatisant and Jelmer Vernooij reported that python-aiohttp is prone to an
open redirect vulnerability. A maliciously crafted link to an aiohttp-based
web-server could redirect the browser to a different website (CVE-2021-21330).
                

References

SRPMS

8/core