Описание
ELSA-2024-8834: python-gevent security update (IMPORTANT)
[1.2.2-5]
- Avoid printing TypeError traceback
- gevent.pywsgi: Much improved handling of chunk trailers Backport fix for CVE-2023-41419 Resolves: RHEL-17078
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
python3-gevent
1.2.2-5.el8_10
Oracle Linux x86_64
python3-gevent
1.2.2-5.el8_10
Связанные CVE
Связанные уязвимости
CVSS3: 9.8
ubuntu
больше 1 года назад
An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.
CVSS3: 9.1
redhat
почти 2 года назад
An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.
CVSS3: 9.8
nvd
больше 1 года назад
An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.
CVSS3: 9.8
github
больше 1 года назад
Gevent allows remote attacker to escalate privileges