mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-09-08 18:30:16 +00:00
Analysis: - The upstream advisory limits the issue to aiohttp applications running on Windows and identifies the affected and fixed versions [1]. - The advisory-selected upstream fix rejects absolute static resource paths, explicitly including UNC and Windows drive paths [2]. - NVD independently describes the issue as Windows-specific and records the same upstream commit as the patch [3]. - Hence ignoring the CVE for now. Reference: [1] https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m [2] https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d [3] https://nvd.nist.gov/vuln/detail/CVE-2026-34515 Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
32 lines
1004 B
BlitzBasic
32 lines
1004 B
BlitzBasic
SUMMARY = "Async http client/server framework"
|
|
DESCRIPTION = "Asynchronous HTTP client/server framework for asyncio and Python"
|
|
HOMEPAGE = "https://github.com/aio-libs/aiohttp"
|
|
LICENSE = "Apache-2.0"
|
|
LIC_FILES_CHKSUM = "file://LICENSE.txt;md5=748073912af33aa59430d3702aa32d41"
|
|
|
|
SRC_URI[sha256sum] = "edea7d15772ceeb29db4aff55e482d4bcfb6ae160ce144f2682de02f6d693551"
|
|
|
|
SRC_URI += "file://CVE-2024-52304.patch \
|
|
file://CVE-2025-53643.patch \
|
|
file://CVE-2025-69225.patch \
|
|
file://CVE-2025-69226.patch \
|
|
file://CVE-2025-69228.patch \
|
|
"
|
|
|
|
CVE_STATUS[CVE-2026-34515] = "not-applicable-platform: Vulnerability only affects applications running on Windows"
|
|
|
|
PYPI_PACKAGE = "aiohttp"
|
|
inherit python_setuptools_build_meta pypi
|
|
|
|
RDEPENDS:${PN} = "\
|
|
python3-aiohappyeyeballs \
|
|
python3-aiosignal \
|
|
python3-async-timeout \
|
|
python3-attrs \
|
|
python3-frozenlist \
|
|
python3-misc \
|
|
python3-multidict \
|
|
python3-yarl \
|
|
python3-aiodns \
|
|
"
|