First published: Wed May 22 2024(Updated: )
Gunicorn (Green Unicorn) is a Python WSGI HTTP server for UNIX<br>Security Fix(es):<br><li> HTTP Request Smuggling due to improper validation of Transfer-Encoding</li> headers (CVE-2024-1135)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-gunicorn | <20.0.4-7.el9 | 20.0.4-7.el9 |
redhat/python3-gunicorn | <20.0.4-7.el9 | 20.0.4-7.el9 |
Red Hat OpenStack Services on OpenShift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:2727 is classified as important.
To fix RHSA-2024:2727, update to python-gunicorn and python3-gunicorn version 20.0.4-7.el9 or later.
RHSA-2024:2727 addresses an HTTP Request Smuggling vulnerability due to improper validation of Transfer-Encoding headers.
RHSA-2024:2727 affects Red Hat OpenStack and the Gunicorn packages in the specified versions.
CVE-2024-1135 is the identifier for the vulnerability involving HTTP Request Smuggling addressed in RHSA-2024:2727.