aiohttp-session creates non-expiring sessions
Moderate severity
GitHub Reviewed
Published
Dec 20, 2018
to the GitHub Advisory Database
•
Updated Aug 30, 2024
Description
Published to the GitHub Advisory Database
Dec 20, 2018
Reviewed
Jun 16, 2020
Last updated
Aug 30, 2024
aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.
References