RHSA-2024:9976: Important: RHOSP 17.1.4 (python-werkzeug) security update
Important: RHOSP 17.1.4 (python-werkzeug) security update
Other sources
Werkzeug is a WSGI utility module. It includes a debugger, request andresponse objects, HTTP utilities to handle entity tags, cache controlheaders, HTTP dates, cookie handling, file uploads, a URL routing systemand a numerous community contributed add-on modules. Werkzeug is unicodeaware and does not enforce a specific template engine, database adapter ora specific way of handling requests. It is useful for end userapplications, such as blogs, wikis, and bulletin boards, that need tooperate in a wide variety of server environments.Security Fix(es): user may execute code on a developer's machine (CVE-2024-34069) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:9976?
The severity of RHSA-2024:9976 is classified as important.
How do I fix RHSA-2024:9976?
You can fix RHSA-2024:9976 by updating the python-werkzeug and python3-werkzeug packages to version 2.0.1-7.el9.
What products are affected by RHSA-2024:9976?
The affected products for RHSA-2024:9976 include Red Hat OpenStack and the python-werkzeug package.
Is RHSA-2024:9976 a specific vulnerability?
Yes, RHSA-2024:9976 addresses a security vulnerability in the Werkzeug WSGI utility module.
When was the RHSA-2024:9976 advisory issued?
The advisory for RHSA-2024:9976 was issued for a security update regarding the Werkzeug module.