Important: Red Hat OpenStack Platform 17.1 (python-h11) security update
Important: Red Hat OpenStack Platform 18.0 (python-h11) security update
Django is a high-level Python Web framework that encourages rapid<br>development and a clean, pragmatic design. It focuses on automating as much<br>as possible and adhering to the DRY (Don't Repeat Yourself) principle.<br>Security Fix(es):<br><li> Potential regular expression denial-of-service in</li> django.utils.text.Truncator.words() (CVE-2024-27351)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Ironic is a project which aims to provision bare metal (as opposed tovirtual) machines by leveraging common technologies such as PXE boot andIPMI to cover a wide range of hardware, while supporting pluggable driversto allow vendor-specific functionality to be added.Bare Metal provisioningfor OpenStackSecurity Fix(es): Lack of checksum validation on images (CVE-2024-47211) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
An ansible-core rebuild for OpenStack based on python 3.9.Security Fix(es): Jinja sandbox breakout through attr filter selecting format method (CVE-2025-27516)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Important: Red Hat OpenStack Platform 17.1 (python-waitress) security update
A highly-available key value store for shared configurationSecurity Fix(es): golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Important: Red Hat OpenStack Platform 17.1 (python-waitress) security update
A high-level Python Web framework<br>Security Fix(es):<br><li> python-django20: jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods (CVE-2020-11023)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.
Ironic is a project which aims to provision bare metal (as opposed tovirtual) machines by leveraging common technologies such as PXE boot andIPMI to cover a wide range of hardware, while supporting pluggable driversto allow vendor-specific functionality to be added.Bare Metal provisioningfor OpenStackSecurity Fix(es): Lack of checksum validation on images (CVE-2024-47211) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> golang: Calling Decoder.Decode on a message which contains deeply nested</li> structures can cause a panic due to stack exhaustion (CVE-2024-34156)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Important: Red Hat OpenStack Platform 16.2 (python-waitress) security update
Important: Red Hat OpenStack Platform 16.2 (openstack-ironic) security update
Important: Red Hat OpenStack Platform 16.2 (osp-director-operator) security update
Moderate: RHOSP 17.1.4 (openstack-tripleo-common and python-tripleoclient) security update
Important: RHOSP 17.1.4 (openstack-ironic) security update
Moderate: RHOSP 17.1.4 (python-webob) security update
Moderate: RHOSP 17.1.4 (python-urllib3) security update
Heat templates for TripleOSecurity Fix(es): cleartext passwords exposed in logs (CVE-2024-4840) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Moderate: RHOSP 17.1.4 (openstack-tripleo-common and python-tripleoclient) security update
Moderate: RHOSP 17.1.4 (python-webob) security update
Important: RHOSP 17.1.4 (python-werkzeug) security update
Important: RHOSP 17.1.4 (python-werkzeug) security update
Moderate: RHOSP 17.1.4 (python-sqlparse) security update
Moderate: RHOSP 17.1.4 (python-requests) security update
Django is a high-level Python Web framework that encourages rapiddevelopment and a clean, pragmatic design. It focuses on automating as muchas possible and adhering to the DRY (Don't Repeat Yourself) principle.Security Fix(es): Potential denial-of-service in django.utils.html.urlize() (CVE-2024-38875) Potential denial-of-service in django.utils.translation.getsupportedlanguagevariant() (CVE-2024-39614) Username enumeration through timing difference for users with unusable passwords (CVE-2024-39329) Potential directory-traversal in django.core.files.storage.Storage.save() (CVE-2024-39330)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Moderate: Red Hat OpenStack Platform 18.0 (python-webob) security update
Important: Red Hat OpenStack Platform 16.1.9 (openstack-nova) security update
Important: Red Hat OpenStack Platform 17.1.3 security update
Important: Red Hat OpenStack Platform 17.1.3 security update