CVE-2018-1000814
aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.
- Affected products
- Aiohttp-Session
- Aio-libs Aiohttp Session
- ≤ 2.6.0
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 1.0% (58th percentile)
- Weakness
- CWE-613
- NVD status
- Modified
- Published
- 2018-12-20
CVE-2018-1000814 at NVD
No indexed exploits for CVE-2018-1000814 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-1000814 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.