CVE-2024-23334Disclosure(aiohttp / aiohttp)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if reading a file is within the root directory. This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present. Disabling follow_symlinks and using a reverse proxy are encouraged mitigations. Version 3.9.2 fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aiohttp
  • fedora

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
aiohttpfedora

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-16: 1Technical Details · 2026-02-16: 102-16
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0xR0_@Pylonetwork
    Disclosure

    🚀 Presento CVE De La Semana, un proyecto donde analizaré vulnerabilidades reales explicando cómo surgen y cómo pueden explotarse. 🔎 Primera publicación: CVE-2024-23334 (Path Traversal en aiohttp) https://cvedelasemana.github.io/posts/cve-2024-23334/

    Post summary

    A blog post introduces CVE-2024-23334, a path traversal vulnerability in aiohttp, outlining its mechanics and potential exploitation, but does not provide PoC, patch information, or evidence of wild attacks.

    11020112
    234 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appaiohttpaiohttp---
OSfedoraprojectfedora39--

Explore more