CGSI Probes: ShadowSyndicate's Aiohttp CVE-2024-23334
ID: c97a2e93-bfb6-5a2d-a4be-e5104eeaae78
STIX ID: report--c97a2e93-bfb6-5a2d-a4be-e5104eeaae78
Feed Name: Cyble Blog
This advisory describes CVE-2024-23334, a directory traversal vulnerability in aiohttp (pre-3.9.2) with CVSS 7.5 that allows unauthenticated remote access to arbitrary files; a public PoC and accompanying video were released and CGSI observed active scanning starting Feb 29, 2024. The report highlights ~43,000 Internet-exposed aiohttp instances, lists observed attacker IPs, and attributes some scanning to the ShadowSyndicate ransomware-affiliated group, urging immediate patching to 3.9.2 and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
