rpm package
almalinux/fence-agents-common
pkg:rpm/almalinux/fence-agents-common
Vulnerabilities (24)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-45803 | Med | 4.2 | < 4.10.0-62.el9 | 4.10.0-62.el9 | Oct 17, 2023 | urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GE | |
| CVE-2023-43804 | Med | 5.9 | < 4.10.0-55.el9_3.2.alma.1 | 4.10.0-55.el9_3.2.alma.1 | Oct 4, 2023 | urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unk | |
| CVE-2023-37920 | Hig | 7.5 | < 4.10.0-55.el9_3.2.alma.1 | 4.10.0-55.el9_3.2.alma.1 | Jul 25, 2023 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an invest | |
| CVE-2022-36087 | Med | 5.7 | < 4.10.0-43.el9 | 4.10.0-43.el9 | Sep 9, 2022 | OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it i |
- affected < 4.10.0-62.el9fixed 4.10.0-62.el9
urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GE
- affected < 4.10.0-55.el9_3.2.alma.1fixed 4.10.0-55.el9_3.2.alma.1
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unk
- affected < 4.10.0-55.el9_3.2.alma.1fixed 4.10.0-55.el9_3.2.alma.1
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an invest
- affected < 4.10.0-43.el9fixed 4.10.0-43.el9
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it i
Page 2 of 2