RHSA-2024:2733: Moderate: Red Hat OpenStack Platform 17.1 (openstack-ansible-core) security update
An ansible-core rebuild for OpenStack based on python 3.9.Security Fix(es): HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Other sources
Moderate: Red Hat OpenStack Platform 17.1 (openstack-ansible-core) security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2733?
The severity of RHSA-2024:2733 is indicated by the associated CVE-2024-22195, which presents a risk of HTML attribute injection.
How do I fix RHSA-2024:2733?
To mitigate RHSA-2024:2733, update the 'openstack-ansible-core' package to version 2.14.2-4.3.el9 or later.
Which software is affected by RHSA-2024:2733?
RHSA-2024:2733 affects Red Hat Enterprise Linux for x86_64, Red Hat OpenStack Director Deployment Tools, and Red Hat OpenStack.
What kind of vulnerability is described in RHSA-2024:2733?
RHSA-2024:2733 describes a vulnerability related to HTML attribute injection due to improper handling of user input in the xmlattr filter.
What is CVE-2024-22195 related to RHSA-2024:2733?
CVE-2024-22195 is the specific identifier for the vulnerability that allows HTML attribute injection as noted in RHSA-2024:2733.