RHSA-2024:9975: Important: RHOSP 17.1.4 (python-werkzeug) security update
Important: RHOSP 17.1.4 (python-werkzeug) security update
Other sources
Werkzeug is a WSGI utility module. It includes a debugger, request andresponse objects, HTTP utilities to handle entity tags, cache controlheaders, HTTP dates, cookie handling, file uploads, a URL routing systemand a numerous community contributed add-on modules. Werkzeug is unicodeaware and does not enforce a specific template engine, database adapter ora specific way of handling requests. It is useful for end userapplications, such as blogs, wikis, and bulletin boards, that need tooperate in a wide variety of server environments.Security Fix(es): user may execute code on a developer's machine (CVE-2024-34069) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:9975?
The severity of RHSA-2024:9975 is classified as important.
How do I fix RHSA-2024:9975?
To fix RHSA-2024:9975, update the python-werkzeug and python3-werkzeug packages to version 2.0.1-9.el8.
Which products are affected by RHSA-2024:9975?
RHSA-2024:9975 affects Red Hat OpenStack and the python-werkzeug and python3-werkzeug packages.
What vulnerabilities does RHSA-2024:9975 address?
RHSA-2024:9975 addresses security issues found in the Werkzeug WSGI utility module.
Is there a recommended version to install for RHSA-2024:9975?
Yes, the recommended version to install for RHSA-2024:9975 is 2.0.1-9.el8.