RHSA-2021:3490: Moderate: Red Hat OpenStack Platform 16.2 (python-django20) security update
Security Fix(es): Potential directory-traversal via archive.extract() (CVE-2021-3281) Potential directory traversal via admindocs (CVE-2021-33203) Possible indeterminate SSRF RFI and LFI attacks since validators accepted leading zeros in IPv4 addresses (CVE-2021-33571)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:3490?
The severity of RHSA-2021:3490 is classified as important, indicating a moderate potential impact on the affected systems.
How do I fix RHSA-2021:3490?
To fix RHSA-2021:3490, upgrade to python-django20 version 2.0.13-16.el8 or python3-django20 version 2.0.13-16.el8.
What vulnerabilities are addressed in RHSA-2021:3490?
RHSA-2021:3490 addresses directory traversal vulnerabilities and potential SSRF, RFI, and LFI attacks.
Which packages are affected by RHSA-2021:3490?
The affected packages in RHSA-2021:3490 are python-django20 and python3-django20, both versioned 2.0.13-16.el8.
What is the impact of not addressing RHSA-2021:3490?
Failing to address RHSA-2021:3490 may allow unauthorized access to sensitive directories and potential data compromise.