Where
-Infinity
0
Severity
7

Heat templates for TripleOYAQL library has a out of the box large set of commonly used functions.Security Fix(es): OpenStack Murano Component Information Leakage (CVE-2024-29156) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Heat templates for TripleOYAQL library has a out of the box large set of commonly used functions.Security Fix(es): OpenStack Murano Component Information Leakage (CVE-2024-29156) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1 (collectd-sensubility) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)</li> <li> net/http/internal: Denial of Service (DoS) via Resource Consumption via</li> HTTP requests (CVE-2023-39326)<br><li> crypto/tls: Timing Side Channel attack in RSA based TLS key exchanges.</li> (CVE-2023-45287)<br><li> net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> <li> etcd: Incomplete fix for CVE-2023-39325/CVE-2023-44487 in OpenStack Platform (CVE-2024-4438)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1 (collectd-sensubility) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> Incomplete fix for CVE-2023-39325/CVE-2023-44487 in OpenStack Platform</li> (CVE-2024-4438)<br><li> Incomplete fix for CVE-2021-44716 in OpenStack Platform (CVE-2024-4437)</li> <li> Incomplete fix for CVE-2022-41723 in OpenStack Platform (CVE-2024-4436)</li> <li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> <li> golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)</li> <li> golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)</li> <li> golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)</li> <li> golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)</li> <li> golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1 director Operator container images security update

1 / 2
Source: Red Hat

Remedy

The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io or registry.access.redhat.com using the 'podman pull' command.<br>For more information about the images, search the image name in the Red Hat Ecosystem Catalog: <a href="https://catalog.redhat.com/software/containers/search" target="_blank">https://catalog.redhat.com/software/containers/search</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 16.2 director Operator container images security update

1 / 2
Source: Red Hat

Remedy

The container images provided by this update can be downloaded from the Red Hat container registry at registry.redhat.io or registry.access.redhat.com using the 'podman pull' command.<br>For more information about the images, search the image name in the Red Hat Ecosystem Catalog: <a href="https://catalog.redhat.com/software/containers/search" target="_blank">https://catalog.redhat.com/software/containers/search</a>
First published (updated )
Severity
7

Gunicorn (Green Unicorn) is a Python WSGI HTTP server for UNIX.<br>Security Fix(es):<br><li> HTTP Request Smuggling due to improper validation of Transfer-Encoding</li> headers (CVE-2024-1135)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Affected components:<br><li> python-yaql: a library that contains a large set of commonly used functions</li> <li> openstack-tripleo-heat-templates: Heat templates for TripleO</li> <li> openstack-tripleo-common: Python library for code used by TripleO projects</li> Security Fix(es):<br><li> OpenStack Murano Component Information Leakage (CVE-2024-29156)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 16.1.9 (openstack-nova) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1.3 security update

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1.3 security update

Remedy

Before applying this update, make sure all previously released errata relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHOSP 17.1.4 (openstack-ironic) security update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHOSP 17.1.4 (python-werkzeug) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: RHOSP 17.1.4 (python-werkzeug) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 16.2 (osp-director-operator) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> golang: Calling Decoder.Decode on a message which contains deeply nested</li> structures can cause a panic due to stack exhaustion (CVE-2024-34156)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Race Condition

Important: Red Hat OpenStack Platform 16.2 (python-waitress) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 16.2 (openstack-ironic) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Race Condition

Important: Red Hat OpenStack Platform 17.1 (python-waitress) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

A highly-available key value store for shared configurationSecurity Fix(es): golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Race Condition

Important: Red Hat OpenStack Platform 17.1 (python-waitress) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

An ansible-core rebuild for OpenStack based on python 3.9.Security Fix(es): Jinja sandbox breakout through attr filter selecting format method (CVE-2025-27516)For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVEpage listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1 (python-h11) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 18.0 (python-h11) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1.1 security update

1 / 2

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 17.1.1 (director-operator) security update

1 / 2

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Service Telemetry Framework 1.5.2 security update

1 / 2

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

gevent is a coroutine-based Python networking library that uses greenlet to provide a high-level synchronous API on top of libevent event loop.Security Fix(es): python-gevent: privilege escalation via a crafted script to the WSGIServer component (CVE-2023-41419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203