RHSA-2024:2734: Moderate: Red Hat OpenStack Platform 17.1 (python-urllib3) security update
Moderate: Red Hat OpenStack Platform 17.1 (python-urllib3) security update
Other sources
Python HTTP module with connection pooling and file POST abilities.<br>Security Fix(es):<br><li> Request body not stripped after redirect from 303 status changes request</li> method to GET (CVE-2023-45803)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2734?
The severity of RHSA-2024:2734 is classified as moderate.
How do I fix RHSA-2024:2734?
To fix RHSA-2024:2734, update the python-urllib3 and python3-urllib3 packages to version 1.25.10-6.el8.
What does the RHSA-2024:2734 vulnerability affect?
RHSA-2024:2734 affects the Red Hat OpenStack Platform 17.1 and several associated products using the python-urllib3 package.
What vulnerability does RHSA-2024:2734 address?
RHSA-2024:2734 addresses a vulnerability where the request body is not stripped after a 303 redirect, changing the request method to GET (CVE-2023-45803).
Is RHSA-2024:2734 specific to a certain version of Python?
Yes, RHSA-2024:2734 is specific to the urllib3 module in Python.