Bug 1774605
Summary: | Ceph 4 building outdated 8 years old version of python-repoze-lru | ||
---|---|---|---|
Product: | [Red Hat Storage] Red Hat Ceph Storage | Reporter: | Hardik Vyas <hvyas> |
Component: | Distribution | Assignee: | Timothy Asir <tjeyasin> |
Status: | CLOSED ERRATA | QA Contact: | Sunil Angadi <sangadi> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 4.0 | CC: | epuertat, pnataraj, sangadi, tjeyasin, tserlin |
Target Milestone: | --- | ||
Target Release: | 4.2 | ||
Hardware: | Unspecified | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | python-repoze-lru-0.7-6.el8ost, python-repoze-lru-0.7-8.el7cp | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2021-01-12 14:55:53 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Hardik Vyas
2019-11-20 14:37:39 UTC
Is the package being used by anyone? The exact dependency chain is: ceph-dashboard -> python3-cherrypy -> python3-routes -> python3-repoze-lru. I couldn't find any CVEs for repoze-lru package, and checked the commit history between 0.4..0.7, and ~6 commits out of 85 are bugfixes (the remaining are Python 2-3 compatibility-related, docs, tests/coverage, new functionality and clean-ups). None of those bugfixes seem security related. @Timothy, nevertheless, could you please take care of looking how to upgrade python3-repoze-lru to a newer version? Thanks! Any news? (In reply to Ernesto Puerta from comment #2) > The exact dependency chain is: ceph-dashboard -> python3-cherrypy -> > python3-routes -> python3-repoze-lru. > > I couldn't find any CVEs for repoze-lru package, and checked the commit > history between 0.4..0.7, and ~6 commits out of 85 are bugfixes (the > remaining are Python 2-3 compatibility-related, docs, tests/coverage, new > functionality and clean-ups). None of those bugfixes seem security related. > > @Timothy, nevertheless, could you please take care of looking how to upgrade > python3-repoze-lru to a newer version? Thanks! Sure @Ernesto. Thank you! Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (Important: Red Hat Ceph Storage 4.2 Security and Bug Fix update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2021:0081 |