aiohttp-session creates non-expiring sessions
High severity
GitHub Reviewed
Published
Dec 20, 2018
to the GitHub Advisory Database
•
Updated Mar 14, 2025
Description
Published by the National Vulnerability Database
Dec 20, 2018
Published to the GitHub Advisory Database
Dec 20, 2018
Reviewed
Jun 16, 2020
Last updated
Mar 14, 2025
aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.
References