Search CVE reports


Toggle filters

311 – 320 of 829 results


CVE-2023-5625

Medium priority
Not affected

A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.

1 affected package

python-eventlet

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-eventlet Not affected Not affected Not affected
Show less packages

CVE-2023-5752

Medium priority
Ignored

When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie...

1 affected package

python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-45803

Medium priority

Some fixes available 13 of 16

urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one...

2 affected packages

python-pip, python-urllib3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Not affected Fixed Fixed Fixed Fixed
python-urllib3 Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2018-25091

Medium priority

Some fixes available 4 of 7

urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be...

2 affected packages

python-pip, python-urllib3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Not affected Not affected Not affected Not affected Fixed
python-urllib3 Not affected Not affected Not affected Not affected Fixed
Show less packages

CVE-2023-43804

Medium priority

Some fixes available 12 of 15

urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it...

2 affected packages

python-pip, python-urllib3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Not affected Not affected Fixed Fixed Fixed
python-urllib3 Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-43665

Medium priority

Some fixes available 10 of 12

In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain...

1 affected package

python-django

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-django Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-26151

Medium priority
Needs evaluation

Versions of the package asyncua before 0.9.96 are vulnerable to Denial of Service (DoS) such that an attacker can send a malformed packet and as a result, the server will enter into an infinite loop and consume excessive memory.

1 affected package

python-opcua

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-opcua Not in release Not in release Needs evaluation Ignored Ignored
Show less packages

CVE-2023-26150

Medium priority
Needs evaluation

Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication. **Note:** This issue is a result of missing checks...

1 affected package

python-opcua

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-opcua Not in release Not in release Needs evaluation Ignored Ignored
Show less packages

CVE-2023-41419

Medium priority
Vulnerable

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

1 affected package

python-gevent

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-gevent Not affected Not affected Vulnerable Needs evaluation Needs evaluation
Show less packages

CVE-2019-19450

Medium priority
Needs evaluation

paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary...

1 affected package

python-reportlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-reportlab Not affected Not affected Not affected Not affected Needs evaluation
Show less packages