Python-eventlet: patch regression for cve-2021-21419 in some red hat builds
CVE-2023-5625
7.5HIGH
Key Information:
- Vendor
- Red Hat
- Status
- Vendor
- CVE Published:
- 1 November 2023
Summary
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.
Affected Version(s)
Ironic content for Red Hat OpenShift Container Platform 4.12 0:0.30.2-4.el9
Red Hat OpenStack Platform 17.1 for RHEL 8 0:0.30.2-4.el8ost
Red Hat OpenStack Platform 17.1 for RHEL 9 0:0.30.2-4.el9ost
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database