RHSA-2024:9991: Moderate: RHOSP 17.1.4 (openstack-tripleo-common and python-tripleoclient) security update
Moderate: RHOSP 17.1.4 (openstack-tripleo-common and python-tripleoclient) security update
Other sources
Python library for code used by TripleO projectsa Python TripleOClient for Openstack DirectorSecurity Fix(es): RHOSP Director Disables TLS Verification for Registry Mirrors (CVE-2024-8007)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:9991?
The severity of RHSA-2024:9991 is classified as Moderate.
How do I fix RHSA-2024:9991?
To fix RHSA-2024:9991, update the affected packages to the specified remedial versions for openstack-tripleo-common and python-tripleoclient.
What are the affected packages in RHSA-2024:9991?
The affected packages in RHSA-2024:9991 include openstack-tripleo-common, python-tripleoclient, and their container counterparts.
Why is TLS verification disabled for registry mirrors in RHSA-2024:9991?
TLS verification is disabled for registry mirrors in RHSA-2024:9991 to address security vulnerabilities that could arise from improper SSL validation.
What should I do if I am using Red Hat OpenStack with the CVE indicated in RHSA-2024:9991?
If you are using Red Hat OpenStack, ensure you apply the security update provided in RHSA-2024:9991 urgently to mitigate any associated risks.