UNIX symbolic link following in aiohttp - CVE-2024-42367

 

UNIX symbolic link following in aiohttp - CVE-2024-42367

Published: August 14, 2024


Vulnerability identifier: #VU96003
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-42367
CWE-ID: CWE-61
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a symlink following issue when handling static routes which contain files with compressed variants in the FileResponse class even when "follow_symlinks=False" is set. A remote attacker can pass a specially crafted file to the application and perform directory traversal attacks.


Affected software

aiohttp
IBM Cloud Pak for Security
IBM Process Mining
Siebel CRM Cloud Applications
Anolis OS
openEuler
QRadar Suite
python-aiohttp
python-aiohttp-debuginfo
python-aiohttp-debugsource
python-aiohttp-help
python3-aiohttp
python3-aiohttp+speedups

How to mitigate CVE-2024-42367

Install updates from vendor's website.

aiohttp - update to 3.10.2
IBM Process Mining - update to 2.0
QRadar Suite - update to 1.10.26.0
python-aiohttp - update to 3.9.3-5
python-aiohttp-debuginfo - update to 3.9.3-5
python-aiohttp-debugsource - update to 3.9.3-5
python-aiohttp-help - update to 3.9.3-5
python3-aiohttp - update to 3.9.3-5
python3-aiohttp+speedups - update to 3.9.5-2
python3-aiohttp - update to 3.9.5-2

External References

Related Security Bulletins