First published: Thu Nov 21 2024(Updated: )
Moderate: RHOSP 17.1.4 (python-urllib3) security update
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-urllib3 | <1.25.10-7.el8 | 1.25.10-7.el8 |
redhat/python3-urllib3 | <1.25.10-7.el8 | 1.25.10-7.el8 |
Red Hat OpenStack Director Deployment Tools | ||
Red Hat Enterprise Linux 8 | ||
Red Hat OpenStack Services on OpenShift |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:9985 is classified as moderate.
To fix RHSA-2024:9985, update the 'python-urllib3' and 'python3-urllib3' packages to version 1.25.10-7.el8.
RHSA-2024:9985 addresses a vulnerability where the proxy-authorization request header is not stripped during cross-origin redirects (CVE-2024-37891).
RHSA-2024:9985 affects Red Hat OpenStack Director Deployment Tools, Red Hat Enterprise Linux for x86_64, and Red Hat OpenStack.
The security fix in RHSA-2024:9985 is significant as it mitigates potential security risks associated with improper handling of proxy-authorization headers during redirects.