[GHSA-v6wp-4m6f-gcjg] Open redirect vulnerability in normalize_path_middleware middleware #5497
Closed
Description
🐞 Describe the bug
$sbj. A maliciously constructed link could trick an aiohttp app using normalize_path_middleware to issue an HTTP redirect to a foreign website. But not anymore. Fixed in v3.7.4.
📋 Logs/tracebacks
See GHSA-v6wp-4m6f-gcjg.
📋 Additional context
OWASP: https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
Our security policy: https://github.com/aio-libs/aiohttp/security/policy (TL;DR — never report security bugs in public, use designated emails for this)
👏 Credits