-
-
Notifications
You must be signed in to change notification settings - Fork 2.2k
[GHSA-v6wp-4m6f-gcjg] Open redirect vulnerability in normalize_path_middleware middleware #5497
Copy link
Copy link
Closed
Labels
bugreproducer: presentThis PR or issue contains code, which reproduce the problem described or clearly understandable STRThis PR or issue contains code, which reproduce the problem described or clearly understandable STRserver
Description
🐞 Describe the bug
$sbj. A maliciously constructed link could trick an aiohttp app using normalize_path_middleware to issue an HTTP redirect to a foreign website. But not anymore. Fixed in v3.7.4.
📋 Logs/tracebacks
See GHSA-v6wp-4m6f-gcjg.
📋 Additional context
Our security policy: https://github.com/aio-libs/aiohttp/security/policy (TL;DR — never report security bugs in public, use designated emails for this)
👏 Credits
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
bugreproducer: presentThis PR or issue contains code, which reproduce the problem described or clearly understandable STRThis PR or issue contains code, which reproduce the problem described or clearly understandable STRserver