CVE Vulnerabilities

CVE-2023-5625

Published: Nov 01, 2023 | Modified: Jan 16, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.

Affected Software

Name Vendor Start Version End Version
Openshift_container_platform_for_arm64 Redhat 4.12 (including) 4.12 (including)
Openshift_container_platform_for_linuxone Redhat 4.12 (including) 4.12 (including)
Openshift_container_platform_for_power Redhat 4.12 (including) 4.12 (including)
Openshift_container_platform_ibm_z_systems Redhat 4.12 (including) 4.12 (including)
Ironic content for Red Hat OpenShift Container Platform 4.12 RedHat python-eventlet-0:0.30.2-4.el9 *
Red Hat OpenStack Platform 17.1 for RHEL 8 RedHat python-eventlet-0:0.30.2-4.el8ost *
Red Hat OpenStack Platform 17.1 for RHEL 9 RedHat python-eventlet-0:0.30.2-4.el9ost *
Python-eventlet Ubuntu bionic *
Python-eventlet Ubuntu trusty *
Python-eventlet Ubuntu xenial *

References