package/python-aiohttp: security bump to version 3.7.4
authorPeter Korsgaard <peter@korsgaard.com>
Sat, 27 Feb 2021 12:38:44 +0000 (13:38 +0100)
committerYann E. MORIN <yann.morin.1998@free.fr>
Sat, 27 Feb 2021 15:55:28 +0000 (16:55 +0100)
commit0e60a9aa835a2141d4f8e382dc736862a29f6e7f
tree21adfcfe5780fd0d9377f94d47e7fca4694a5fe0
parent908d96717051c5b57566638c7566372553c6e148
package/python-aiohttp: security bump to version 3.7.4

Fixes the following security issue:

CVE-2021-21330: Open redirect vulnerability in aiohttp
(normalize_path_middleware middleware)

Beast Glatisant and Jelmer Vernooij reported that python-aiohttp, a async
HTTP client/server framework, is prone to an open redirect vulnerability.  A
maliciously crafted link to an aiohttp-based web-server could redirect the
browser to a different website.

For more details, see the advisory:
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-v6wp-4m6f-gcjg

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/python-aiohttp/python-aiohttp.hash
package/python-aiohttp/python-aiohttp.mk