An issue in Gevent Gevent before version 23.9.1 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component. Reference: https://github.com/gevent/gevent/issues/1989 Upstream patch: https://github.com/gevent/gevent/commit/2f53c851eaf926767fbac62385615efd4886221c
Created python-gevent tracking bugs for this issue: Affects: fedora-all [bug 2242244]
This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 Via RHSA-2023:7438 https://access.redhat.com/errata/RHSA-2023:7438
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2024:7421 https://access.redhat.com/errata/RHSA-2024:7421
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2024:7785 https://access.redhat.com/errata/RHSA-2024:7785
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2024:8105 https://access.redhat.com/errata/RHSA-2024:8105
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:8102 https://access.redhat.com/errata/RHSA-2024:8102
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:8834 https://access.redhat.com/errata/RHSA-2024:8834