USN-5386-1: AIOHTTP vulnerability
21 April 2022
AIOHTTP could be used to perform an open redirect attack.
Releases
Packages
- python-aiohttp - http client/server for asyncio
Details
Jelmer Vernooij and Beast Glatisant discovered that AIOHTTP incorrectly
handled certain URLs, leading to an open redirect attack. A remote
attacker could possibly use this issue to perform phishing attacks.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
-
python3-aiohttp
-
3.6.2-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04
-
python3-aiohttp
-
3.0.1-1ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.