Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT. https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
I can’t update python-socketio past 5.11.4-1 in Fedora 41. I don’t remember if this is for dependency reasons or compatibility / breaking change reasons, but I remember that there were good reasons. It should be possible to backport the fix from https://github.com/miguelgrinberg/python-socketio/commit/53f6be094257ed81476b0e212c8cddd6d06ca39a to 5.11.4, and I considered doing so, but the patch is not very small, and there has been quite a bit of change upstream since 5.11.4, so the risk of introducing a regression or accidental incompatibility is not quite small enough to ignore. Considering this, my doubts that the particular circumstances in which this can be exploited (“multi-server deployments on which the attacker previously gained access to the message queue that the servers use for internal communications”) can ever occur when python-socketio is used as a dependency for pgadmin4, and the mere month and a half remaining until Fedora 41 end-of-life, I’m not planning to prepare an update for this issue in Fedora 41. Users who are concerned about this CVE should consider expediting their plans to upgrade to Fedora 42 or 43, where updates that would resolve this CVE are now in testing.