First published: Thu Jul 25 2024(Updated: )
Security Fix(es):<br><li> python: Path traversal on tempfile.TemporaryDirectory (CVE-2023-6597)</li> <li> python: The zipfile module is vulnerable to zip-bombs leading to denial of</li> service (CVE-2024-0450)<br><li> skupper: potential authentication bypass to skupper console via forged cookies (CVE-2024-6535)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2024:4871 addresses critical vulnerabilities including path traversal and zip-bomb denial of service issues.
To fix RHSA-2024:4871, ensure that your software is updated to the latest patched versions provided by Red Hat.
RHSA-2024:4871 includes security vulnerabilities such as CVE-2023-6597 and CVE-2024-0450.
If exploited, the vulnerabilities in RHSA-2024:4871 could lead to unauthorized access and potential denial of service.
In the absence of an immediate update, it's advisable to restrict access to potentially vulnerable components as a temporary measure.