Description
aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0001 | aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value. |
Github GHSA |
GHSA-mr4x-c4v9-x729 | aiohttp-session creates non-expiring sessions |
References
History
Fri, 14 Mar 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aio-libs
Aio-libs aiohttp Session |
|
| CPEs | cpe:2.3:a:aio-libs:aiohttp_session:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aiohttp-session Project
Aiohttp-session Project aiohttp-session |
Aio-libs
Aio-libs aiohttp Session |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T01:01:46.072Z
Reserved: 2018-12-20T00:00:00.000Z
Link: CVE-2018-1000814
No data.
Status : Modified
Published: 2018-12-20T15:29:00.487
Modified: 2025-03-14T14:09:33.920
Link: CVE-2018-1000814
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA