Sploitus

CVE-2018-1000814

No indexed exploits for CVE-2018-1000814 yet

aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.

Affected products
Aiohttp-Session
Aio-libs Aiohttp Session
≤ 2.6.0
CVSS 3.1
6.5 MEDIUM
EPSS
1.0% (58th percentile)
Weakness
CWE-613
NVD status
Modified
Published
2018-12-20
CVE-2018-1000814 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2018-1000814 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2018-1000814 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.