Lucene search

K
oraclelinuxOracleLinuxELSA-2024-6162
HistorySep 03, 2024 - 12:00 a.m.

python-urllib3 security update

2024-09-0300:00:00
linux.oracle.com
33
python
urllib3
security update
cve-2024-37891
rhel-49853

CVSS3

4.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

Low

[1.26.5-5.1]

  • Security fix for CVE-2024-37891
  • Backport upstream patch to fix TypeError for http connection if the PoolManager
  • is instantiated with server_hostname
    Resolves: RHEL-49853

CVSS3

4.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

Low