CVE-2018-1000814

aio-libs aiohttp-session version 2.6.0 and earlier contains a Other/Unknown vulnerability in EncryptedCookieStorage and NaClCookieStorage that can result in Non-expiring sessions / Infinite lifespan. This attack appear to be exploitable via Recreation of a cookie post-expiry with the same value.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:aio-libs:aiohttp_session:*:*:*:*:*:*:*:*

History

14 Mar 2025, 14:09

Type Values Removed Values Added
First Time Aio-libs
Aio-libs aiohttp Session
CPE cpe:2.3:a:aiohttp-session_project:aiohttp-session:*:*:*:*:*:*:*:* cpe:2.3:a:aio-libs:aiohttp_session:*:*:*:*:*:*:*:*

Information

Published : 2018-12-20 15:29

Updated : 2025-03-14 14:09


NVD link : CVE-2018-1000814

Mitre link : CVE-2018-1000814

CVE.ORG link : CVE-2018-1000814


JSON object : View

Products Affected

aio-libs

  • aiohttp_session
CWE
CWE-613

Insufficient Session Expiration