Where
-Infinity
0
Severity
7

Important: Red Hat OpenStack Platform 17.1 (python-h11) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 18.0 (python-h11) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Django is a high-level Python Web framework that encourages rapid<br>development and a clean, pragmatic design. It focuses on automating as much<br>as possible and adhering to the DRY (Don't Repeat Yourself) principle.<br>Security Fix(es):<br><li> Potential regular expression denial-of-service in</li> django.utils.text.Truncator.words() (CVE-2024-27351)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Ironic is a project which aims to provision bare metal (as opposed tovirtual) machines by leveraging common technologies such as PXE boot andIPMI to cover a wide range of hardware, while supporting pluggable driversto allow vendor-specific functionality to be added.Bare Metal provisioningfor OpenStackSecurity Fix(es): Lack of checksum validation on images (CVE-2024-47211) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

An ansible-core rebuild for OpenStack based on python 3.9.Security Fix(es): Jinja sandbox breakout through attr filter selecting format method (CVE-2025-27516)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Race Condition

Important: Red Hat OpenStack Platform 17.1 (python-waitress) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

A highly-available key value store for shared configurationSecurity Fix(es): golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Race Condition

Important: Red Hat OpenStack Platform 17.1 (python-waitress) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

A high-level Python Web framework<br>Security Fix(es):<br><li> python-django20: jquery: Untrusted code execution via &lt;option&gt; tag in HTML passed to DOM manipulation methods (CVE-2020-11023)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Ironic is a project which aims to provision bare metal (as opposed tovirtual) machines by leveraging common technologies such as PXE boot andIPMI to cover a wide range of hardware, while supporting pluggable driversto allow vendor-specific functionality to be added.Bare Metal provisioningfor OpenStackSecurity Fix(es): Lack of checksum validation on images (CVE-2024-47211) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata relevant<br>to your system have been applied.<br>For details on how to apply this update as a new RHOSO 18.0 deployment, see “Deploying Red Hat OpenStack Services on OpenShift” at <a href="https://docs.redhat.com/en/documentation/red_hat_openstack_services_on_openshift/18.0/html/deploying_red_hat_openstack_services_on_openshift/index" target="_blank">https://docs.redhat.com/en/documentation/red_hat_openstack_services_on_openshift/18.0/html/deploying_red_hat_openstack_services_on_openshift/index</a> For details on how to apply this update to an existing RHOSO 18.0 deployment, see "Updating your environment to the latest maintenance release" at <a href="https://docs.redhat.com/en/documentation/red_hat_openstack_services_on_openshift/18.0/html/updating_your_environment_to_the_latest_maintenance_release/index" target="_blank">https://docs.redhat.com/en/documentation/red_hat_openstack_services_on_openshift/18.0/html/updating_your_environment_to_the_latest_maintenance_release/index</a>
First published (updated )
Severity
7

A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> golang: Calling Decoder.Decode on a message which contains deeply nested</li> structures can cause a panic due to stack exhaustion (CVE-2024-34156)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Race Condition

Important: Red Hat OpenStack Platform 16.2 (python-waitress) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 16.2 (openstack-ironic) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 16.2 (osp-director-operator) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Moderate: RHOSP 17.1.4 (openstack-tripleo-common and python-tripleoclient) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHOSP 17.1.4 (openstack-ironic) security update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Moderate: RHOSP 17.1.4 (python-webob) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Moderate: RHOSP 17.1.4 (python-urllib3) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Heat templates for TripleOSecurity Fix(es): cleartext passwords exposed in logs (CVE-2024-4840) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Moderate: RHOSP 17.1.4 (openstack-tripleo-common and python-tripleoclient) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Moderate: RHOSP 17.1.4 (python-webob) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHOSP 17.1.4 (python-werkzeug) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHOSP 17.1.4 (python-werkzeug) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Moderate: RHOSP 17.1.4 (python-sqlparse) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Moderate: RHOSP 17.1.4 (python-requests) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Django is a high-level Python Web framework that encourages rapiddevelopment and a clean, pragmatic design. It focuses on automating as muchas possible and adhering to the DRY (Don't Repeat Yourself) principle.Security Fix(es): Potential denial-of-service in django.utils.html.urlize() (CVE-2024-38875) Potential denial-of-service in django.utils.translation.getsupportedlanguagevariant() (CVE-2024-39614) Username enumeration through timing difference for users with unusable passwords (CVE-2024-39329) Potential directory-traversal in django.core.files.storage.Storage.save() (CVE-2024-39330)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update as a new RHOSO 18.0 deployment, see<br>“Deploying Red Hat OpenStack Services on OpenShift” at<br><a href="https://docs.redhat.com/en/documentation/red_hat_openstack_services_on_openshift/18.0/html/deploying_red_hat_openstack_services_on_openshift/index" target="_blank">https://docs.redhat.com/en/documentation/red_hat_openstack_services_on_openshift/18.0/html/deploying_red_hat_openstack_services_on_openshift/index</a> For details on how to apply this update to an existing RHOSO 18.0 deployment, see "Updating your environment to the latest maintenance release" at<br><a href="https://docs.redhat.com/en/documentation/red_hat_openstack_services_on_openshift/18.0/html/updating_your_environment_to_the_latest_maintenance_release/index" target="_blank">https://docs.redhat.com/en/documentation/red_hat_openstack_services_on_openshift/18.0/html/updating_your_environment_to_the_latest_maintenance_release/index</a>
First published (updated )
Severity
4

Moderate: Red Hat OpenStack Platform 18.0 (python-webob) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 16.1.9 (openstack-nova) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1.3 security update

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1.3 security update

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203