aiohttp-session@2.5.1 vulnerabilities

sessions for aiohttp.web

Direct Vulnerabilities

Known vulnerabilities in the aiohttp-session package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Insufficient Session Expiration

aiohttp-session provides sessions for aiohttp.web.

Affected versions of this package are vulnerable to Insufficient Session Expiration via the EncryptedCookieStorage and NaClCookieStorage functions that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.

How to fix Insufficient Session Expiration?

Upgrade aiohttp-session to version 2.7.0 or higher.

[,2.7.0)