RHSA-2024:9983: Moderate: RHOSP 17.1.4 (python-webob) security update
Moderate: RHOSP 17.1.4 (python-webob) security update
Other sources
WebOb provides wrappers around the WSGI request environment, and an objectto help create WSGI responses. The objects map much of the specifiedbehavior of HTTP, including header parsing and accessors for other standardparts of the environment.Security Fix(es): WebOb's location header normalization during redirect leads to open redirect (CVE-2024-42353)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:9983?
The severity of RHSA-2024:9983 is classified as moderate.
How do I fix RHSA-2024:9983?
To fix RHSA-2024:9983, update the python-webob and python3-webob packages to version 1.8.7-2.1.el9.
Which products are affected by RHSA-2024:9983?
RHSA-2024:9983 affects Red Hat Enterprise Linux for x86_64 and Red Hat OpenStack.
What components does RHSA-2024:9983 address?
RHSA-2024:9983 addresses vulnerabilities in the WebOb library, which is used for WSGI requests and responses.
What is WebOb in relation to RHSA-2024:9983?
WebOb is a Python library that provides wrappers for WSGI requests and responses and is impacted by security vulnerabilities in RHSA-2024:9983.