First published: Tue Nov 21 2023(Updated: )
gevent is a coroutine-based Python networking library that uses greenlet to provide a high-level synchronous API on top of libevent event loop.<br>Security Fix(es):<br><li> python-gevent: privilege escalation via a crafted script to the WSGIServer component (CVE-2023-41419)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-gevent | <21.1.2-2.el9 | 21.1.2-2.el9 |
redhat/python-gevent-debugsource | <21.1.2-2.el9 | 21.1.2-2.el9 |
redhat/python3-gevent | <21.1.2-2.el9 | 21.1.2-2.el9 |
redhat/python3-gevent-debuginfo | <21.1.2-2.el9 | 21.1.2-2.el9 |
Red Hat OpenStack Services on OpenShift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2023:7438 is high with a severity value of 7.
Red Hat OpenStack Platform 17.1.1 and python-gevent, python-gevent-debugsource, python3-gevent, python3-gevent-debuginfo packages are affected.
You can fix RHSA-2023:7438 by updating the affected software to version 21.1.2-2.el9.
You can find more information about RHSA-2023:7438 on the Red Hat Customer Portal and Bugzilla.
RHSA-2023:7438 has the source 'redhat' and the package 'python-gevent'.