8000 Security: aiohttp dependency vulnerability in botbuilder-ai 4.16.2 · Issue #2205 · microsoft/botbuilder-python · GitHub
[go: up one dir, main page]

Skip to content
8000

Security: aiohttp dependency vulnerability in botbuilder-ai 4.16.2 #2205

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
3 tasks
louspringer opened this issue Feb 11, 2025 · 0 comments
Open
3 tasks

Comments

@louspringer
Copy link

Security vulnerability in dependency chain preventing critical updates. See full details in docs/security/msrc-report-2024-03.md

Quick Summary

  • botbuilder-ai 4.16.2 requires aiohttp==3.10.5
  • aiohttp 3.10.5 has known vulnerabilities (CVE-2024-52303, CVE-2024-52304)
  • Cannot update to secure aiohttp 3.10.11 due to strict version constraint

Impact

  • Medium to High severity
  • Affects all Bot Framework applications using botbuilder-ai
  • Remote exploitation possible

Status

  • Submit to Microsoft Security Response Center
  • Implement temporary mitigations
  • Monitor for upstream fix

Next Steps

  1. Submit detailed report to Microsoft
  2. Implement protective middleware
  3. Document workarounds for users

References

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant
0