RHSA-2021:5070: Moderate: Red Hat OpenStack Platform 16.1 (python-django20) security update
Security Fix(es): Potential directory-traversal via archive.extract() (CVE-2021-3281) potential directory-traversal via uploaded files (CVE-2021-28658) Potential directory-traversal via uploaded files (CVE-2021-31542) Potential directory traversal via admindocs (CVE-2021-33203) Possible indeterminate SSRF RFI and LFI attacks since validators accepted leading zeros in IPv4 addresses (CVE-2021-33571)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-django20to a version that resolves this vulnerability.Fixed in 2.0.13-16.el8 - Upgrade
Upgrade
redhat/python-django20-bash-completionto a version that resolves this vulnerability.Fixed in 2.0.13-16.el8 - Upgrade
Upgrade
redhat/python3-django20to a version that resolves this vulnerability.Fixed in 2.0.13-16.el8
Event History
Frequently Asked Questions
What vulnerabilities are addressed by RHSA-2021:5070?
RHSA-2021:5070 addresses potential directory-traversal vulnerabilities via archive.extract() and uploaded files.
What is the severity of RHSA-2021:5070?
The severity of RHSA-2021:5070 is classified as important due to the potential impact of directory traversal attacks.
How do I fix the vulnerabilities in RHSA-2021:5070?
To fix the vulnerabilities in RHSA-2021:5070, update the affected packages to versions 2.0.13-16.el8 or later.
Which packages are affected by RHSA-2021:5070?
The affected packages in RHSA-2021:5070 include python-django20, python-django20-bash-completion, and python3-django20.
Is RHSA-2021:5070 applicable to my system?
RHSA-2021:5070 is applicable to systems using Red Hat Enterprise Linux 8 with the affected packages installed.