Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 11 |
CVE-ID | CVE-2022-2990 CVE-2022-3259 CVE-2022-41717 CVE-2022-41723 CVE-2022-41724 CVE-2022-41725 CVE-2023-0056 CVE-2023-0229 CVE-2023-0778 CVE-2023-25577 CVE-2023-25725 |
CWE-ID | CWE-863 CWE-693 CWE-770 CWE-400 CWE-399 CWE-20 CWE-284 CWE-367 CWE-444 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #3 is available. |
Vulnerable software |
Red Hat OpenShift Container Platform Client/Desktop applications / Software for system administration openshift4-aws-iso (Red Hat package) Operating systems & Components / Operating system package or component openshift-kuryr (Red Hat package) Operating systems & Components / Operating system package or component nmstate (Red Hat package) Operating systems & Components / Operating system package or component haproxy (Red Hat package) Operating systems & Components / Operating system package or component fuse-overlayfs (Red Hat package) Operating systems & Components / Operating system package or component containernetworking-plugins (Red Hat package) Operating systems & Components / Operating system package or component atomic-openshift-service-idler (Red Hat package) Operating systems & Components / Operating system package or component toolbox (Red Hat package) Operating systems & Components / Operating system package or component skopeo (Red Hat package) Operating systems & Components / Operating system package or component runc (Red Hat package) Operating systems & Components / Operating system package or component python-wsme (Red Hat package) Operating systems & Components / Operating system package or component python-uhashring (Red Hat package) Operating systems & Components / Operating system package or component python-trustme (Red Hat package) Operating systems & Components / Operating system package or component python-tooz (Red Hat package) Operating systems & Components / Operating system package or component python-swiftclient (Red Hat package) Operating systems & Components / Operating system package or component python-sushy-oem-idrac (Red Hat package) Operating systems & Components / Operating system package or component python-sushy (Red Hat package) Operating systems & Components / Operating system package or component python-stevedore (Red Hat package) Operating systems & Components / Operating system package or component python-service-identity (Red Hat package) Operating systems & Components / Operating system package or component python-scciclient (Red Hat package) Operating systems & Components / Operating system package or component python-requestsexceptions (Red Hat package) Operating systems & Components / Operating system package or component python-pyfakefs (Red Hat package) Operating systems & Components / Operating system package or component python-pycadf (Red Hat package) Operating systems & Components / Operating system package or component python-proliantutils (Red Hat package) Operating systems & Components / Operating system package or component python-osprofiler (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-versionedobjects (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-utils (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-upgradecheck (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-service (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-serialization (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-rootwrap (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-policy (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-middleware (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-metrics (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-messaging (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-log (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-i18n (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-db (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-context (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-config (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-concurrency (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-cache (Red Hat package) Operating systems & Components / Operating system package or component python-osc-lib (Red Hat package) Operating systems & Components / Operating system package or component python-os-traits (Red Hat package) Operating systems & Components / Operating system package or component python-os-service-types (Red Hat package) Operating systems & Components / Operating system package or component python-openstacksdk (Red Hat package) Operating systems & Components / Operating system package or component python-mistune (Red Hat package) Operating systems & Components / Operating system package or component python-m2r (Red Hat package) Operating systems & Components / Operating system package or component python-keystonemiddleware (Red Hat package) Operating systems & Components / Operating system package or component python-keystoneclient (Red Hat package) Operating systems & Components / Operating system package or component python-keystoneauth1 (Red Hat package) Operating systems & Components / Operating system package or component python-ironic-prometheus-exporter (Red Hat package) Operating systems & Components / Operating system package or component python-ironic-lib (Red Hat package) Operating systems & Components / Operating system package or component python-importlib-metadata (Red Hat package) Operating systems & Components / Operating system package or component python-hardware (Red Hat package) Operating systems & Components / Operating system package or component python-greenlet (Red Hat package) Operating systems & Components / Operating system package or component python-glanceclient (Red Hat package) Operating systems & Components / Operating system package or component python-futurist (Red Hat package) Operating systems & Components / Operating system package or component python-fasteners (Red Hat package) Operating systems & Components / Operating system package or component python-eventlet (Red Hat package) Operating systems & Components / Operating system package or component python-dracclient (Red Hat package) Operating systems & Components / Operating system package or component python-debtcollector (Red Hat package) Operating systems & Components / Operating system package or component python-cliff (Red Hat package) Operating systems & Components / Operating system package or component python-cinderclient (Red Hat package) Operating systems & Components / Operating system package or component python-binary-memcached (Red Hat package) Operating systems & Components / Operating system package or component python-automaton (Red Hat package) Operating systems & Components / Operating system package or component podman (Red Hat package) Operating systems & Components / Operating system package or component ovn23.03 (Red Hat package) Operating systems & Components / Operating system package or component ovn22.12 (Red Hat package) Operating systems & Components / Operating system package or component openvswitch3.1 (Red Hat package) Operating systems & Components / Operating system package or component openvswitch3.0 (Red Hat package) Operating systems & Components / Operating system package or component openstack-ironic-python-agent (Red Hat package) Operating systems & Components / Operating system package or component openstack-ironic-inspector (Red Hat package) Operating systems & Components / Operating system package or component openstack-ironic (Red Hat package) Operating systems & Components / Operating system package or component openshift-clients (Red Hat package) Operating systems & Components / Operating system package or component openshift-ansible (Red Hat package) Operating systems & Components / Operating system package or component openshift (Red Hat package) Operating systems & Components / Operating system package or component kernel-rt (Red Hat package) Operating systems & Components / Operating system package or component kernel (Red Hat package) Operating systems & Components / Operating system package or component kata-containers (Red Hat package) Operating systems & Components / Operating system package or component crun (Red Hat package) Operating systems & Components / Operating system package or component cri-tools (Red Hat package) Operating systems & Components / Operating system package or component cri-o (Red Hat package) Operating systems & Components / Operating system package or component coreos-installer (Red Hat package) Operating systems & Components / Operating system package or component containers-common (Red Hat package) Operating systems & Components / Operating system package or component container-selinux (Red Hat package) Operating systems & Components / Operating system package or component conmon-rs (Red Hat package) Operating systems & Components / Operating system package or component conmon (Red Hat package) Operating systems & Components / Operating system package or component buildah (Red Hat package) Operating systems & Components / Operating system package or component python-werkzeug (Red Hat package) Operating systems & Components / Operating system package or component tini (Red Hat package) Operating systems & Components / Operating system package or component python-pyghmi (Red Hat package) Operating systems & Components / Operating system package or component python-paste (Red Hat package) Operating systems & Components / Operating system package or component python-packaging (Red Hat package) Operating systems & Components / Operating system package or component python-kubernetes (Red Hat package) Operating systems & Components / Operating system package or component python-flask (Red Hat package) Operating systems & Components / Operating system package or component grpc (Red Hat package) Operating systems & Components / Operating system package or component ansible-runner-http (Red Hat package) Operating systems & Components / Operating system package or component ansible-runner (Red Hat package) Operating systems & Components / Operating system package or component python-zope-interface (Red Hat package) Operating systems & Components / Operating system package or component python-zipp (Red Hat package) Operating systems & Components / Operating system package or component python-zeroconf (Red Hat package) Operating systems & Components / Operating system package or component python-zake (Red Hat package) Operating systems & Components / Operating system package or component python-yappi (Red Hat package) Operating systems & Components / Operating system package or component python-wrapt (Red Hat package) Operating systems & Components / Operating system package or component python-webtest (Red Hat package) Operating systems & Components / Operating system package or component python-webob (Red Hat package) Operating systems & Components / Operating system package or component python-warlock (Red Hat package) Operating systems & Components / Operating system package or component python-waitress (Red Hat package) Operating systems & Components / Operating system package or component python-voluptuous (Red Hat package) Operating systems & Components / Operating system package or component python-virtualenv (Red Hat package) Operating systems & Components / Operating system package or component python-vine (Red Hat package) Operating systems & Components / Operating system package or component python-unittest2 (Red Hat package) Operating systems & Components / Operating system package or component python-typeguard (Red Hat package) Operating systems & Components / Operating system package or component python-traceback2 (Red Hat package) Operating systems & Components / Operating system package or component python-tox-current-env (Red Hat package) Operating systems & Components / Operating system package or component python-testresources (Red Hat package) Operating systems & Components / Operating system package or component python-testrepository (Red Hat package) Operating systems & Components / Operating system package or component python-tenacity (Red Hat package) Operating systems & Components / Operating system package or component python-tempita (Red Hat package) Operating systems & Components / Operating system package or component python-stestr (Red Hat package) Operating systems & Components / Operating system package or component python-statsd (Red Hat package) Operating systems & Components / Operating system package or component python-sqlparse (Red Hat package) Operating systems & Components / Operating system package or component python-sqlalchemy (Red Hat package) Operating systems & Components / Operating system package or component python-smi (Red Hat package) Operating systems & Components / Operating system package or component python-singledispatch (Red Hat package) Operating systems & Components / Operating system package or component python-simplejson (Red Hat package) Operating systems & Components / Operating system package or component python-simplegeneric (Red Hat package) Operating systems & Components / Operating system package or component python-routes (Red Hat package) Operating systems & Components / Operating system package or component python-rfc3986 (Red Hat package) Operating systems & Components / Operating system package or component python-requests-unixsocket (Red Hat package) Operating systems & Components / Operating system package or component python-repoze-lru (Red Hat package) Operating systems & Components / Operating system package or component python-redis (Red Hat package) Operating systems & Components / Operating system package or component python-pytest-xprocess (Red Hat package) Operating systems & Components / Operating system package or component python-pytest-xdist (Red Hat package) Operating systems & Components / Operating system package or component python-pymemcache (Red Hat package) Operating systems & Components / Operating system package or component python-prometheus_client (Red Hat package) Operating systems & Components / Operating system package or component python-pretend (Red Hat package) Operating systems & Components / Operating system package or component python-pint (Red Hat package) Operating systems & Components / Operating system package or component python-pexpect (Red Hat package) Operating systems & Components / Operating system package or component python-pecan (Red Hat package) Operating systems & Components / Operating system package or component python-paste-deploy (Red Hat package) Operating systems & Components / Operating system package or component python-oslotest (Red Hat package) Operating systems & Components / Operating system package or component python-oslo-reports (Red Hat package) Operating systems & Components / Operating system package or component python-os-client-config (Red Hat package) Operating systems & Components / Operating system package or component python-nose-cover3 (Red Hat package) Operating systems & Components / Operating system package or component python-neutronclient (Red Hat package) Operating systems & Components / Operating system package or component python-munch (Red Hat package) Operating systems & Components / Operating system package or component python-msgpack (Red Hat package) Operating systems & Components / Operating system package or component python-mox3 (Red Hat package) Operating systems & Components / Operating system package or component python-more-itertools (Red Hat package) Operating systems & Components / Operating system package or component python-migrate (Red Hat package) Operating systems & Components / Operating system package or component python-memcached (Red Hat package) Operating systems & Components / Operating system package or component python-markupsafe (Red Hat package) Operating systems & Components / Operating system package or component python-logutils (Red Hat package) Operating systems & Components / Operating system package or component python-linecache2 (Red Hat package) Operating systems & Components / Operating system package or component python-kiwisolver (Red Hat package) Operating systems & Components / Operating system package or component python-keyring (Red Hat package) Operating systems & Components / Operating system package or component python-kazoo (Red Hat package) Operating systems & Components / Operating system package or component python-kafka (Red Hat package) Operating systems & Components / Operating system package or component python-jsonpath-rw (Red Hat package) Operating systems & Components / Operating system package or component python-itsdangerous (Red Hat package) Operating systems & Components / Operating system package or component python-iso8601 (Red Hat package) Operating systems & Components / Operating system package or component python-ironicclient (Red Hat package) Operating systems & Components / Operating system package or component python-ifaddr (Red Hat package) Operating systems & Components / Operating system package or component python-hacking (Red Hat package) Operating systems & Components / Operating system package or component python-gunicorn (Red Hat package) Operating systems & Components / Operating system package or component python-gevent (Red Hat package) Operating systems & Components / Operating system package or component python-funcsigs (Red Hat package) Operating systems & Components / Operating system package or component python-entrypoints (Red Hat package) Operating systems & Components / Operating system package or component python-editor (Red Hat package) Operating systems & Components / Operating system package or component python-dogpile-cache (Red Hat package) Operating systems & Components / Operating system package or component python-defusedxml (Red Hat package) Operating systems & Components / Operating system package or component python-decorator (Red Hat package) Operating systems & Components / Operating system package or component python-ddt (Red Hat package) Operating systems & Components / Operating system package or component python-dataclasses (Red Hat package) Operating systems & Components / Operating system package or component python-coverage (Red Hat package) Operating systems & Components / Operating system package or component python-construct (Red Hat package) Operating systems & Components / Operating system package or component python-colorama (Red Hat package) Operating systems & Components / Operating system package or component python-case (Red Hat package) Operating systems & Components / Operating system package or component python-cachetools (Red Hat package) Operating systems & Components / Operating system package or component python-bcrypt (Red Hat package) Operating systems & Components / Operating system package or component python-amqp (Red Hat package) Operating systems & Components / Operating system package or component python-alembic (Red Hat package) Operating systems & Components / Operating system package or component python-SecretStorage (Red Hat package) Operating systems & Components / Operating system package or component pysnmp (Red Hat package) Operating systems & Components / Operating system package or component openstack-macros (Red Hat package) Operating systems & Components / Operating system package or component crudini (Red Hat package) Operating systems & Components / Operating system package or component libslirp (Red Hat package) Operating systems & Components / Operating system package or component criu (Red Hat package) Operating systems & Components / Operating system package or component python-wcwidth (Red Hat package) Operating systems & Components / Operating system package or component python-pyperclip (Red Hat package) Operating systems & Components / Operating system package or component python-pycdlib (Red Hat package) Operating systems & Components / Operating system package or component python-cmd2 (Red Hat package) Operating systems & Components / Operating system package or component python-pyrsistent (Red Hat package) Operating systems & Components / Operating system package or component python-jsonschema (Red Hat package) Operating systems & Components / Operating system package or component python-rsa (Red Hat package) Operating systems & Components / Operating system package or component python-pyroute2 (Red Hat package) Operating systems & Components / Operating system package or component python-lockfile (Red Hat package) Operating systems & Components / Operating system package or component |
Vendor | Red Hat Inc. |
Security Bulletin
This security bulletin contains information about 11 vulnerabilities.
EUVDB-ID: #VU69291
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-2990
CWE-ID:
CWE-863 - Incorrect Authorization
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect handling of the supplementary groups in the Buildah container engine. A local user with direct access to the affected container where supplementary groups are used can set access permissions and execute a binary code in that container. MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU71362
Risk: Low
CVSSv4.0: 0.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-3259
CWE-ID:
CWE-693 - Protection Mechanism Failure
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to missing HTTP Strict Transport Security (HSTS) header. A remote attacker can perform MitM attack.
Install updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU70334
Risk: Medium
CVSSv4.0: 5.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/U:Green]
CVE-ID: CVE-2022-41717
CWE-ID:
CWE-770 - Allocation of Resources Without Limits or Throttling
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to excessive memory growth when handling HTTP/2 server requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU72686
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-41723
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources in the HPACK decoder. A remote attacker can send a specially crafted HTTP/2 stream to the application, cause resource exhaustion and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72685
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-41724
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources in crypto/tls when handling large TLS handshake records. A remote attacker can send specially crafted data to the application and perform a denial of service (DoS) attack.
The vulnerability affects all TLS 1.3 clients, TLS 1.2 clients which explicitly enable session resumption (by setting Config.ClientSessionCache to a non-nil value), and TLS 1.3 servers which request client certificates (by setting Config.ClientAuth >= RequestClientCert).
MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU73722
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-41725
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper control over internal resources in net/http and mime/multipart. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU71431
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-0056
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the http_wait_for_response() function when handling HTTP/2 requests. A remote attacker can send a specially crafted HTTP request the proxy server and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74481
Risk: Low
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-0229
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to disable seccomp for pods they can create and modify.
MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU74843
Risk: Medium
CVSSv4.0: 1.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-0778
CWE-ID:
CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain compromise the affected system.
The vulnerability exists due to a race condition. A remote attacker can replace a normal file in a volume with a symlink while exporting the volume, allowing for access to arbitrary files on the host file system.
MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72339
Risk: Medium
CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-25577
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when parsing multipart form data with many fields. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU72334
Risk: Medium
CVSSv4.0: 1.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-25725
CWE-ID:
CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform HTTP request smuggling attacks.
The vulnerability exists due to improper validation of HTTP/1 requests. A remote attacker can send a specially crafted HTTP request with empty fields, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1
Successful exploitation of vulnerability may allow an attacker to poison HTTP cache and perform phishing attacks.
MitigationInstall updates from vendor's website.
Red Hat OpenShift Container Platform: before 4.13.0
openshift4-aws-iso (Red Hat package): before 4.13.0-202304052215.p0.gd2acdd5.assembly.stream.el8
openshift-kuryr (Red Hat package): before 4.13.0-202304192042.p0.g4fe6bbc.assembly.stream.el8
nmstate (Red Hat package): before 2.2.9-6.rhaos4.13.el8
haproxy (Red Hat package): before 2.2.24-3.rhaos4.13.el8
fuse-overlayfs (Red Hat package): before 1.10-2.rhaos4.13.el8
containernetworking-plugins (Red Hat package): before 1.0.1-6.rhaos4.13.el8
atomic-openshift-service-idler (Red Hat package): before 4.13.0-202303172327.p0.ga0f9090.assembly.stream.el8
toolbox (Red Hat package): before 0.1.2-1.rhaos4.13.el9
skopeo (Red Hat package): before 1.10.0-1.rhaos4.13.el9
runc (Red Hat package): before 1.1.6-3.rhaos4.13.el8
python-wsme (Red Hat package): before 0.11.0-0.20221128135154.80bda90.el9
python-uhashring (Red Hat package): before 2.1-2.el9
python-trustme (Red Hat package): before 0.7.0-1.el9
python-tooz (Red Hat package): before 3.2.0-0.20221128162335.1a76dd6.el9
python-swiftclient (Red Hat package): before 4.1.0-0.20221128153149.662e530.el9
python-sushy-oem-idrac (Red Hat package): before 5.0.0-0.20221128204359.da9a0e4.el9
python-sushy (Red Hat package): before 4.4.3-0.20230425095526.9f708cf.el9
python-stevedore (Red Hat package): before 4.1.0-0.20221128161654.9eb8094.el9
python-service-identity (Red Hat package): before 18.1.0-9.1.el9
python-scciclient (Red Hat package): before 0.12.3-0.20221128150506.0940a71.el9
python-requestsexceptions (Red Hat package): before 1.4.0-0.20221128134625.d7ac0ff.el9
python-pyfakefs (Red Hat package): before 4.4.0-4.el9
python-pycadf (Red Hat package): before 3.1.1-0.20221128135153.4179996.el9
python-proliantutils (Red Hat package): before 2.14.0-0.20221128154535.de9759c.el9
python-osprofiler (Red Hat package): before 3.4.3-0.20221128140710.3286301.el9
python-oslo-versionedobjects (Red Hat package): before 3.0.1-0.20221128145846.2b12029.el9
python-oslo-utils (Red Hat package): before 6.0.1-0.20221128145135.760deb9.el9
python-oslo-upgradecheck (Red Hat package): before 2.0.0-0.20221128142932.b3a2b19.el9
python-oslo-service (Red Hat package): before 3.0.0-0.20221128144658.a27acfe.el9
python-oslo-serialization (Red Hat package): before 4.2.0-0.20211012151454.2b94a4f.el8
python-oslo-rootwrap (Red Hat package): before 6.3.1-0.20221128140202.1b1b960.el9
python-oslo-policy (Red Hat package): before 3.8.2-0.20211012161944.c7fd9f4.el8
python-oslo-middleware (Red Hat package): before 5.0.0-0.20221128142027.51e1882.el9
python-oslo-metrics (Red Hat package): before 0.3.0-0.20211020174122.43eee50.el8
python-oslo-messaging (Red Hat package): before 12.9.1-0.20211020204149.f9de265.el8
python-oslo-log (Red Hat package): before 4.6.0-0.20211012154701.41c8807.el8
python-oslo-i18n (Red Hat package): before 5.1.0-0.20211012165753.b031d17.el8
python-oslo-db (Red Hat package): before 9.1.0-0.20211020204148.be2cc6a.el8
python-oslo-context (Red Hat package): before 3.3.1-0.20211012152439.641a1e0.el8
python-oslo-config (Red Hat package): before 8.7.1-0.20211012155707.1a7bd66.el8
python-oslo-concurrency (Red Hat package): before 5.0.1-0.20221129205158.01cf2ff.el9
python-oslo-cache (Red Hat package): before 3.1.0-0.20221129203427.7fb06bc.el9
python-osc-lib (Red Hat package): before 2.6.2-0.20221128150506.d438afa.el9
python-os-traits (Red Hat package): before 2.9.0-0.20221128153153.fc91a78.el9
python-os-service-types (Red Hat package): before 1.7.0-0.20221128134625.0b2f473.el9
python-openstacksdk (Red Hat package): before 0.102.0-0.20221128160622.9a17781.el9
python-mistune (Red Hat package): before 0.8.3-15.1.el9
python-m2r (Red Hat package): before 0.2.1-3.1.20190604git66f4a5a.el9
python-keystonemiddleware (Red Hat package): before 10.1.0-0.20221128152538.f7ac6a1.el9
python-keystoneclient (Red Hat package): before 5.0.1-0.20221128145838.bc8e9e7.el9
python-keystoneauth1 (Red Hat package): before 5.0.0-0.20221128144522.2445a5d.el9
python-ironic-prometheus-exporter (Red Hat package): before 3.1.1-0.20221128155706.eb27243.el9
python-ironic-lib (Red Hat package): before 5.3.0-0.20221128152640.340a4b2.el9
python-importlib-metadata (Red Hat package): before 1.7.0-1.el8ost
python-hardware (Red Hat package): before 0.30.0-0.20221128155150.f6ff0ed.el9
python-greenlet (Red Hat package): before 1.1.3-1.el9
python-glanceclient (Red Hat package): before 4.1.0-0.20221128153803.f2999ce.el9
python-futurist (Red Hat package): before 2.4.1-0.20221128140910.159d752.el9
python-fasteners (Red Hat package): before 0.18-1.el9
python-eventlet (Red Hat package): before 0.30.2-1.el8
python-dracclient (Red Hat package): before 8.0.0-0.20221128135758.9c7499c.el9
python-debtcollector (Red Hat package): before 2.5.0-0.20221128140303.a6b46c5.el9
python-cliff (Red Hat package): before 4.0.0-0.20221128185800.58c853d.el9
python-cinderclient (Red Hat package): before 9.1.0-0.20221128151726.730a8c7.el9
python-binary-memcached (Red Hat package): before 0.31.1-1.el9
python-automaton (Red Hat package): before 3.0.1-0.20221128143847.0ea747e.el9
podman (Red Hat package): before 4.4.1-3.rhaos4.13.el8
ovn23.03 (Red Hat package): before 23.03.0-7.el9fdp
ovn22.12 (Red Hat package): before 22.12.0-25.el9fdp
openvswitch3.1 (Red Hat package): before 3.1.0-10.el9fdp
openvswitch3.0 (Red Hat package): before 3.0.0-28.el9fdp
openstack-ironic-python-agent (Red Hat package): before 9.2.0-0.20221128164006.a167075.el9
openstack-ironic-inspector (Red Hat package): before 11.2.0-0.20221128164644.d83454c.el9
openstack-ironic (Red Hat package): before 21.2.0-0.20221209211422.b70b418.el9
openshift-clients (Red Hat package): before 4.13.0-202303241616.p0.g92b1a3d.assembly.stream.el8
openshift-ansible (Red Hat package): before 4.13.0-202304171417.p0.gb4280f6.assembly.stream.el8
openshift (Red Hat package): before 4.13.0-202304211155.p0.gb404935.assembly.stream.el8
kernel-rt (Red Hat package): before 5.14.0-284.13.1.rt14.298.el9_2
kernel (Red Hat package): before 5.14.0-284.13.1.el9_2
kata-containers (Red Hat package): before 3.0.2-5.el9
crun (Red Hat package): before 1.8.4-1.rhaos4.13.el9
cri-tools (Red Hat package): before 1.26.0-1.el9
cri-o (Red Hat package): before 1.26.3-3.rhaos4.13.git641290e.el9
coreos-installer (Red Hat package): before 0.17.0-1.rhaos4.13.el9
containers-common (Red Hat package): before 1-35.rhaos4.13.el9
container-selinux (Red Hat package): before 2.208.0-2.rhaos4.13.el8
conmon-rs (Red Hat package): before 0.5.1-5.rhaos4.13.git.el9
conmon (Red Hat package): before 2.1.7-1.rhaos4.13.el8
buildah (Red Hat package): before 1.29.1-1.rhaos4.13.el9
python-werkzeug (Red Hat package): before 1.0.1-3.el8ost
tini (Red Hat package): before 0.16.1-1.el8ar
python-pyghmi (Red Hat package): before 1.5.14-2.1.el8ost
python-paste (Red Hat package): before 3.2.4-1.el8ost
python-packaging (Red Hat package): before 20.4-1.el8ost
python-kubernetes (Red Hat package): before 25.3.0-1.el8
python-flask (Red Hat package): before 1.1.1-1.el8ost
grpc (Red Hat package): before 1.18.0-4.el8ost
ansible-runner-http (Red Hat package): before 1.0.0-2.el8ar
ansible-runner (Red Hat package): before 1.4.6-2.el8ar
python-zope-interface (Red Hat package): before 5.4.0-1.el9
python-zipp (Red Hat package): before 0.5.1-2.el8ost
python-zeroconf (Red Hat package): before 0.24.4-1.el8ost
python-zake (Red Hat package): before 0.2.2-19.el9
python-yappi (Red Hat package): before 1.3.1-2.el9
python-wrapt (Red Hat package): before 1.11.2-4.el9
python-webtest (Red Hat package): before 2.0.33-5.el9
python-webob (Red Hat package): before 1.8.5-5.el9
python-warlock (Red Hat package): before 1.3.3-2.el9
python-waitress (Red Hat package): before 2.0.0-2.el9
python-voluptuous (Red Hat package): before 0.11.7-3.el9
python-virtualenv (Red Hat package): before 20.4.4-1.el9
python-vine (Red Hat package): before 5.0.0-3.el9
python-unittest2 (Red Hat package): before 1.1.0-24.el9
python-typeguard (Red Hat package): before 2.9.1-1.el9
python-traceback2 (Red Hat package): before 1.4.0-25.el9
python-tox-current-env (Red Hat package): before 0.0.6-1.el9
python-testresources (Red Hat package): before 2.0.1-2.el9
python-testrepository (Red Hat package): before 0.0.20-20.el9
python-tenacity (Red Hat package): before 6.2.0-1.el8ost
python-tempita (Red Hat package): before 0.5.1-25.el9
python-stestr (Red Hat package): before 2.6.0-8.el9
python-statsd (Red Hat package): before 3.2.1-20.el9
python-sqlparse (Red Hat package): before 0.2.4-10.el9
python-sqlalchemy (Red Hat package): before 1.4.39-2.el9
python-smi (Red Hat package): before 0.3.4-10.el9
python-singledispatch (Red Hat package): before 3.4.0.3-19.el9
python-simplejson (Red Hat package): before 3.17.0-2.el9
python-simplegeneric (Red Hat package): before 0.8.1-18.el9
python-routes (Red Hat package): before 2.4.1-12.el9
python-rfc3986 (Red Hat package): before 1.2.0-6.el9
python-requests-unixsocket (Red Hat package): before 0.1.5-5.el8ar
python-repoze-lru (Red Hat package): before 0.7-7.el9
python-redis (Red Hat package): before 3.3.8-2.el9
python-pytest-xprocess (Red Hat package): before 0.18.1-4.el9
python-pytest-xdist (Red Hat package): before 2.2.1-1.el9
python-pymemcache (Red Hat package): before 3.5.0-1.el9
python-prometheus_client (Red Hat package): before 0.7.1-3.el9
python-pretend (Red Hat package): before 1.0.8-19.el9
python-pint (Red Hat package): before 0.10.1-1.el8ost
python-pexpect (Red Hat package): before 4.6-2.el8ar
python-pecan (Red Hat package): before 1.3.2-10.el9
python-paste-deploy (Red Hat package): before 2.0.1-4.el8ost
python-oslotest (Red Hat package): before 4.4.1-0.20210812115053.aaf3a72.el9
python-oslo-reports (Red Hat package): before 2.3.0-0.20211012151507.f2799dc.el9
python-os-client-config (Red Hat package): before 2.1.0-0.20210722194729.bc96c23.el9
python-nose-cover3 (Red Hat package): before 0.1.0-31.el9
python-neutronclient (Red Hat package): before 7.6.0-0.20211012175718.983f0ab.el9
python-munch (Red Hat package): before 2.3.2-7.el9
python-msgpack (Red Hat package): before 0.6.2-1.el8ost
python-mox3 (Red Hat package): before 1.1.0-0.20210812114029.99a302f.el9
python-more-itertools (Red Hat package): before 7.2.0-3.el9
python-migrate (Red Hat package): before 0.13.0-2.el9
python-memcached (Red Hat package): before 1.58-12.el9
python-markupsafe (Red Hat package): before 2.0.0-2.el9
python-logutils (Red Hat package): before 0.3.5-7.1.el9
python-linecache2 (Red Hat package): before 1.0.0-25.el9
python-kiwisolver (Red Hat package): before 1.1.0-4.el9
python-keyring (Red Hat package): before 21.0.0-2.el9
python-kazoo (Red Hat package): before 2.7.0-2.el9
python-kafka (Red Hat package): before 1.4.3-3.el9
python-jsonpath-rw (Red Hat package): before 1.2.3-23.el9
python-itsdangerous (Red Hat package): before 2.0.1-2.el9
python-iso8601 (Red Hat package): before 0.1.12-9.el9
python-ironicclient (Red Hat package): before 4.9.0-0.20211209154934.6f1be06.el9
python-ifaddr (Red Hat package): before 0.1.6-5.el8ost
python-hacking (Red Hat package): before 1.0.1-0.20210812104123.865398f.el9
python-gunicorn (Red Hat package): before 20.0.4-2.el9
python-gevent (Red Hat package): before 21.1.2-1.el9
python-funcsigs (Red Hat package): before 1.0.2-17.el9
python-entrypoints (Red Hat package): before 0.3-8.el9
python-editor (Red Hat package): before 1.0.4-5.el9
python-dogpile-cache (Red Hat package): before 1.1.5-3.el9
python-defusedxml (Red Hat package): before 0.7.1-1.el9
python-decorator (Red Hat package): before 4.4.0-6.el9
python-ddt (Red Hat package): before 1.4.2-1.el9
python-dataclasses (Red Hat package): before 0.8-2.el9
python-coverage (Red Hat package): before 5.6-0.1b1.el9
python-construct (Red Hat package): before 2.10.56-1.el8ost
python-colorama (Red Hat package): before 0.4.1-2.el9
python-case (Red Hat package): before 1.5.3-5.el9
python-cachetools (Red Hat package): before 3.1.0-4.el9
python-bcrypt (Red Hat package): before 3.1.6-3.el9
python-amqp (Red Hat package): before 5.0.6-1.el9
python-alembic (Red Hat package): before 1.4.2-5.el8ost
python-SecretStorage (Red Hat package): before 2.3.1-9.el9
pysnmp (Red Hat package): before 4.4.12-6.el9
openstack-macros (Red Hat package): before 2020.1.2-1.el9
crudini (Red Hat package): before 0.9.3-4.el9
libslirp (Red Hat package): before 4.4.0-2.rhaos4.11.el8
criu (Red Hat package): before 3.15-4.rhaos4.11.el8
python-wcwidth (Red Hat package): before 0.1.7-14.el8ost
python-pyperclip (Red Hat package): before 1.6.4-6.el8ost
python-pycdlib (Red Hat package): before 1.11.0-3.el8
python-cmd2 (Red Hat package): before 1.4.0-1.1.el8
python-pyrsistent (Red Hat package): before 0.16.0-3.el8ost
python-jsonschema (Red Hat package): before 3.2.0-5.el8ost
python-rsa (Red Hat package): before 4.7-1.el8
python-pyroute2 (Red Hat package): before 0.5.13-1.el8ost
python-lockfile (Red Hat package): before 0.11.0-8.el8ar
CPE2.3https://access.redhat.com/errata/RHSA-2023:1325
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.