Home[1] Files[2] News[3] Contact[4] Add New[5]
- Red Hat Security Advisory 2022-1253-01[6]
- Authored by Red Hat[7] | Site access.redhat.com[8]
-
Red Hat Security Advisory 2022-1253-01 - An update for python-waitress is now available for Red Hat OpenStack Platform 16.2 (Train). Issues addressed include a HTTP request smuggling vulnerability.
- systems | linux[9], redhat[10]
- advisories | CVE-2022-24761[11]
- MD5 |
7ee081e422afea5600a4c1543d33068b - Download[12] | Favorite[13] | View[14]
Change Mirror[15] Download[16]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Important: Red Hat OpenStack Platform 16.2 (python-waitress) security update
Advisory ID: RHSA-2022:1253-01
Product: Red Hat OpenStack Platform
Advisory URL: https://access.redhat.com/errata/RHSA-2022:1253
Issue date: 2022-04-06
CVE Names: CVE-2022-24761
====================================================================
1. Summary:
An update for python-waitress is now available for Red Hat OpenStack
Platform 16.2 (Train).
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat OpenStack Platform 16.2 - noarch
3. Description:
Pure-python WSGI server
Security Fix(es):
* Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
(CVE-2022-24761)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
2065086 - CVE-2022-24761 waitress: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
6. Package List:
Red Hat OpenStack Platform 16.2:
Source:
python-waitress-2.0.0-1.el8ost.src.rpm
noarch:
python3-waitress-2.0.0-1.el8ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2022-24761
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. >. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYk1oGNzjgjWX9erEAQjteg/+Mt2AdQligq44W0Fsjq3icE0sr+1yuL6H
pq6WCzXRxDMEnt2P3QsqB3UI6/6MC748hQ1siWJ1B61jOE7jowWW3n3KMIk8JbN3
BZ2KKtI6K+wq1AYwQYDgAN1SIWec/LI+amzr73mIn/C8nWDTpRmixntgtFbl6FzV
/M1FN3c+1o8JR85ny7w5YjTg1A/ZAQAboKaXnDmkif3Wie1A4mByBVQnLVUHvjSb
nqcacZEODSbfi+Q+ZRhY8BSMpAJH/RCkJm9LgMt5UF2N2o3Dz0jqlbzCy3uDwbNA
43S8OSG0CD2N39NMIMOHAERsAsiL3+zPE6fTR44/7dUk6J3YPVUdDLChwjyLISC1
a70fhyna0WBZ5Vaa9jimsCniaVKfdy2sksjWX4yJgi5V726aYX5EaVAFWXyh6rh3
FOg93Js9jx36R794S9qB1klGsld1Wv02xi+uce70fpT4qhbjBdbtqjObwupike3e
dbiAWJe/bk2/QW04UPmUnobstdcutYNS3S5M799JhOqBwY1fFriUAK1k+APieBho
AeTbfO3auuOALJibzr5oMJObycf9ZcnmWqkmjYIUfqnTcfY2nglf7HliLYzwOX2x
r5Qo+0J0BQ8CrULyAQ6oACd8G7rdEGGHQDoPlQ179bI8jqWYGTupqlfK5X0ThkXu
etPFvB5HZz8»0N
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser.
https://listman.redhat.com/mailman/listinfo/rhsa-announce
File Tags
- ActiveX[22] (932)
- Advisory[23] (77,084)
- Arbitrary[24] (15,027)
- BBS[25] (2,859)
- Bypass[26] (1,541)
- CGI[27] (1,010)
- Code Execution[28] (6,603)
- Conference[29] (668)
- Cracker[30] (797)
- CSRF[31] (3,263)
- DoS[32] (21,682)
- Encryption[33] (2,325)
- Exploit[34] (49,508)
- File Inclusion[35] (4,137)
- File Upload[36] (936)
- Firewall[37] (821)
- Info Disclosure[38] (2,539)
- Intrusion Detection[39] (847)
- Java[40] (2,762)
- JavaScript[41] (791)
- Kernel[42] (5,978)
- Local[43] (13,959)
- Magazine[44] (586)
- Overflow[45] (12,111)
- Perl[46] (1,410)
- PHP[47] (5,036)
- Proof of Concept[48] (2,276)
- Protocol[49] (3,278)
- Python[50] (1,381)
- Remote[51] (29,525)
- Root[52] (3,439)
- Ruby[53] (574)
- Scanner[54] (1,629)
- Security Tool[55] (7,658)
- Shell[56] (3,041)
- Shellcode[57] (1,200)
- Sniffer[58] (879)
- Spoof[59] (2,075)
- SQL Injection[60] (15,952)
- TCP[61] (2,349)
- Trojan[62] (668)
- UDP[63] (866)
- Virus[64] (657)
- Vulnerability[65] (30,319)
- Web[66] (8,941)
- Whitepaper[67] (3,706)
- x86[68] (942)
- XSS[69] (17,265)
- Other[70]
File Archives
- April 2022[71]
- March 2022[72]
- February 2022[73]
- January 2022[74]
- December 2021[75]
- November 2021[76]
- October 2021[77]
- September 2021[78]
- August 2021[79]
- July 2021[80]
- June 2021[81]
- May 2021[82]
- Older[83]
Systems
- AIX[84] (424)
- Apple[85] (1,875)
- BSD[86] (368)
- CentOS[87] (55)
- Cisco[88] (1,911)
- Debian[89] (5,947)
- Fedora[90] (1,690)
- FreeBSD[91] (1,241)
- Gentoo[92] (4,152)
- HPUX[93] (876)
- iOS[94] (316)
- iPhone[95] (108)
- IRIX[96] (220)
- Juniper[97] (67)
- Linux[98] (41,779)
- Mac OS X[99] (683)
- Mandriva[100] (3,105)
- NetBSD[101] (255)
- OpenBSD[102] (477)
- RedHat[103] (11,262)
- Slackware[104] (941)
- Solaris[105] (1,605)
- SUSE[106] (1,444)
- Ubuntu[107] (7,707)
- UNIX[108] (9,040)
- UnixWare[109] (183)
- Windows[110] (6,323)
- Other[111]
- Services
- Security Services[122]
- Hosting By
- Rokasec[123]
Read more https://packetstormsecurity.com/files/166605/RHSA-2022-1253-01.txt


