mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-22 23:10:18 +00:00
7489d887347110a24367ab86989ecdaec19f16d4
Analysis: - The upstream advisory limits the issue to aiohttp applications running on Windows and identifies the affected and fixed versions [1]. - The advisory-selected upstream fix rejects absolute static resource paths, explicitly including UNC and Windows drive paths [2]. - NVD independently describes the issue as Windows-specific and records the same upstream commit as the patch [3]. - Hence ignoring the CVE for now. Reference: [1] https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m [2] https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d [3] https://nvd.nist.gov/vuln/detail/CVE-2026-34515 Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
Collection of layers for the OE-core universe
Main layer maintainer: Anuj Mittal anuj.mittal@oss.qualcomm.com
This repository is a collection of layers to suppliment OE-Core with additional packages, Each layer have designated maintainer Please see the respective READMEs in the layer subdirectories
Languages
BitBake
86.5%
Shell
5.8%
C
2.7%
Roff
1.9%
NASL
1.7%
Other
1.2%