RHSA-2024:9988: Moderate: RHOSP 17.1.4 (python-requests) security update
Moderate: RHOSP 17.1.4 (python-requests) security update
Other sources
Most existing Python modules for sending HTTP requests are extremelyverbose and cumbersome. Python’s built-in urllib2 module provides most ofthe HTTP capabilities you should need, but the API is thoroughly broken.This library is designed to make HTTP requests easy for developers.Security Fix(es): subsequent requests to the same host ignore cert verification (CVE-2024-35195)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:9988?
The severity of RHSA-2024:9988 is categorized as moderate.
What products are affected by RHSA-2024:9988?
RHSA-2024:9988 affects Red Hat OpenStack, Red Hat OpenStack Director Deployment Tools, Red Hat Enterprise Linux for x86_64, and the python-requests and python3-requests packages.
How do I fix RHSA-2024:9988?
To fix RHSA-2024:9988, update the python-requests or python3-requests packages to version 2.25.1-2.el8.
Is there a workaround for RHSA-2024:9988?
No specific workaround has been suggested for RHSA-2024:9988; it is recommended to apply the security update.
When was the RHSA-2024:9988 advisory released?
The RHSA-2024:9988 advisory was released recently, addressing vulnerabilities in Python's requests library.