Heat templates for TripleOYAQL library has a out of the box large set of commonly used functions.Security Fix(es): OpenStack Murano Component Information Leakage (CVE-2024-29156) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Heat templates for TripleOYAQL library has a out of the box large set of commonly used functions.Security Fix(es): OpenStack Murano Component Information Leakage (CVE-2024-29156) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Important: Red Hat OpenStack Platform 17.1 (collectd-sensubility) security update
A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)</li> <li> net/http/internal: Denial of Service (DoS) via Resource Consumption via</li> HTTP requests (CVE-2023-39326)<br><li> crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.</li> (CVE-2023-45287)<br><li> net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> <li> etcd: Incomplete fix for CVE-2023-39325/CVE-2023-44487 in OpenStack Platform (CVE-2024-4438)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Important: Red Hat OpenStack Platform 17.1 (collectd-sensubility) security update
A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> Incomplete fix for CVE-2023-39325/CVE-2023-44487 in OpenStack Platform</li> (CVE-2024-4438)<br><li> Incomplete fix for CVE-2021-44716 in OpenStack Platform (CVE-2024-4437)</li> <li> Incomplete fix for CVE-2022-41723 in OpenStack Platform (CVE-2024-4436)</li> <li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> <li> golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)</li> <li> golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)</li> <li> golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)</li> <li> golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)</li> <li> golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Important: Red Hat OpenStack Platform 17.1 director Operator container images security update
Important: Red Hat OpenStack Platform 16.2 director Operator container images security update
Gunicorn (Green Unicorn) is a Python WSGI HTTP server for UNIX.<br>Security Fix(es):<br><li> HTTP Request Smuggling due to improper validation of Transfer-Encoding</li> headers (CVE-2024-1135)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected components:<br><li> python-yaql: a library that contains a large set of commonly used functions</li> <li> openstack-tripleo-heat-templates: Heat templates for TripleO</li> <li> openstack-tripleo-common: Python library for code used by TripleO projects</li> Security Fix(es):<br><li> OpenStack Murano Component Information Leakage (CVE-2024-29156)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Important: Red Hat OpenStack Platform 16.1.9 (openstack-nova) security update
Important: Red Hat OpenStack Platform 17.1.3 security update
Important: Red Hat OpenStack Platform 17.1.3 security update
Important: RHOSP 17.1.4 (openstack-ironic) security update
Important: RHOSP 17.1.4 (python-werkzeug) security update
Important: RHOSP 17.1.4 (python-werkzeug) security update
Important: Red Hat OpenStack Platform 16.2 (osp-director-operator) security update
A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> golang: Calling Decoder.Decode on a message which contains deeply nested</li> structures can cause a panic due to stack exhaustion (CVE-2024-34156)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Important: Red Hat OpenStack Platform 16.2 (python-waitress) security update
Important: Red Hat OpenStack Platform 16.2 (openstack-ironic) security update
Important: Red Hat OpenStack Platform 17.1 (python-waitress) security update
A highly-available key value store for shared configurationSecurity Fix(es): golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Important: Red Hat OpenStack Platform 17.1 (python-waitress) security update
An ansible-core rebuild for OpenStack based on python 3.9.Security Fix(es): Jinja sandbox breakout through attr filter selecting format method (CVE-2025-27516)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.
Important: Red Hat OpenStack Platform 17.1 (python-h11) security update
Important: Red Hat OpenStack Platform 18.0 (python-h11) security update
Important: Red Hat OpenStack Platform 17.1.1 security update
Important: Red Hat OpenStack Platform 17.1.1 (director-operator) security update
Important: Service Telemetry Framework 1.5.2 security update
gevent is a coroutine-based Python networking library that uses greenlet to provide a high-level synchronous API on top of libevent event loop.Security Fix(es): python-gevent: privilege escalation via a crafted script to the WSGIServer component (CVE-2023-41419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.