Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-41419

Опубликовано: 31 авг. 2023
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

A flaw was found in python-event, which could allow a remote attacker to gain elevated privileges on the system, caused by a flaw in the WSGIServer component. By using a specially crafted script, an attacker can gain elevated privileges.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7python-geventWill not fix
Red Hat OpenShift Container Platform 4python-geventWill not fix
Red Hat OpenStack Platform 16.1python-geventNot affected
Red Hat OpenStack Platform 16.2python-geventNot affected
Red Hat OpenStack Platform 17.0python-geventWill not fix
Red Hat OpenStack Platform 18.0python-geventWill not fix
Red Hat Quay 3quay/quay-rhel8Affected
Red Hat Enterprise Linux 8python-geventFixedRHSA-2024:883405.11.2024
Red Hat Enterprise Linux 8.2 Advanced Update Supportpython-geventFixedRHSA-2024:778508.10.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportpython-geventFixedRHSA-2024:810515.10.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2240651python-gevent: privilege escalation via a crafted script to the WSGIServer component

EPSS

Процентиль: 85%
0.02626
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 1 года назад

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

CVSS3: 9.8
nvd
больше 1 года назад

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

suse-cvrf
больше 1 года назад

Security update for python-gevent

CVSS3: 9.8
github
больше 1 года назад

Gevent allows remote attacker to escalate privileges

oracle-oval
8 месяцев назад

ELSA-2024-8834: python-gevent security update (IMPORTANT)

EPSS

Процентиль: 85%
0.02626
Низкий

9.1 Critical

CVSS3