Open redirect in py3-webob - CVE-2024-42353
Published: August 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to redirect victims to arbitrary URL.
The vulnerability exists due to improper sanitization of user-supplied data. A remote attacker can create a link that leads to a trusted website, however, when clicked, redirects the victim to arbitrary domain.
Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.
Affected software
Storage Ceph
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
Fedora
Public Cloud Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Anolis OS
Oracle Solaris
Red Hat OpenShift Container Platform
runc (Red Hat package)
python-WebOb
containernetworking-plugins (Red Hat package)
python2-WebOb
python3-WebOb
python-WebOb-doc
python3-webob (Ubuntu package)
python-webob (Red Hat package)
python3-webob
python-webob
python3-webob-doc
python311-WebOb
skopeo (Red Hat package)
crun (Red Hat package)
cri-o (Red Hat package)
oath-toolkit (Red Hat package)
container-selinux (Red Hat package)
cephadm-ansible (Red Hat package)
podman (Red Hat package)
openshift-ansible (Red Hat package)
kernel (Red Hat package)
kernel-rt (Red Hat package)
openstack-ironic-python-agent (Red Hat package)
ceph (Red Hat package)
openstack-ironic (Red Hat package)
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Ceph Storage
Red Hat OpenStack
How to mitigate CVE-2024-42353
Red Hat OpenShift Container Platform - addressed in versions 4.12.67, 4.13.52, 4.14.38, 4.14.39, 4.15.35, 4.15.37, 4.16.14, 4.16.15, 4.17.1
Storage Ceph - update to 8.1
Fedora - addressed in versions 2026-53bfd89d67, 2026-505b90c299
runc (Red Hat package) - addressed in versions 1.1.14-1.rhaos4.14.el8, 1.1.14-1.rhaos4.14.el9, 1.1.14-1.rhaos4.16.el8, 1.1.14-1.rhaos4.16.el9
python-WebOb - update to 1.2.3-3.3.1
containernetworking-plugins (Red Hat package) - update to 1.4.0-4.rhaos4.13.el8
python2-WebOb - update to 1.7.4-150000.3.3.1
python3-WebOb - update to 1.7.4-150000.3.3.1
python-WebOb-doc - update to 1.7.4-150000.3.3.1
python3-webob (Ubuntu package) - addressed in versions 1:1.8.5-2ubuntu0.1, 1:1.8.6-1.1ubuntu0.1, 1:1.8.7-1ubuntu0.1.24.04.1
python-webob (Red Hat package) - addressed in versions 1.8.7-2.1.el8ost, 1.8.7-2.1.el9ost, 1.8.7-3.el9ost, 1.8.8-2.el9
python3-webob - update to 1.8.7-3
python-webob - update to 1.8.7-3
python3-webob - update to 1.8.7-3
python3-webob-doc - update to 1.8.7-3
python311-WebOb - update to 1.8.7-150400.11.6.1
python-webob - addressed in versions 1.8.8-1.el8, 1.8.8-1.el9, 1.8.8-1.fc39, 1.8.8-1.fc40, 1.8.8-1.fc41, 1.8.8-1.fc42, 1.8.8-2.el8, 1.8.8-2.el9, 1.8.8-2.fc39, 1.8.8-2.fc40, 1.8.11-1.el8, 1.8.11-1.el9, 1.8.11-1.el10_3, 1.8.11-1.fc43, 1.8.11-1.fc44
skopeo (Red Hat package) - addressed in versions 1.11.3-3.rhaos4.13.el8, 1.11.3-3.rhaos4.13.el9, 1.11.3-3.rhaos4.14.el8, 1.11.3-3.rhaos4.14.el9, 1.11.3-4.rhaos4.15.el8, 1.11.3-4.rhaos4.15.el9
crun (Red Hat package) - addressed in versions 1.17-1.rhaos4.14.el8, 1.17-1.rhaos4.14.el9, 1.17-1.rhaos4.16.el8, 1.17-1.rhaos4.16.el9
cri-o (Red Hat package) - addressed in versions 1.26.5-23.rhaos4.13.git6d9c688.el8, 1.26.5-23.rhaos4.13.git6d9c688.el9, 1.27.8-8.rhaos4.14.git17cbe6d.el8, 1.27.8-8.rhaos4.14.git17cbe6d.el9, 1.28.10-5.rhaos4.15.git7a788e6.el8, 1.28.10-5.rhaos4.15.git7a788e6.el9, 1.29.8-4.rhaos4.16.git7c340a9.el9
oath-toolkit (Red Hat package) - addressed in versions 2.6.12-1.el8cp, 2.6.12-1.el9cp
container-selinux (Red Hat package) - addressed in versions 2.228.1-1.rhaos4.13.el8, 2.228.1-1.rhaos4.13.el9
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4, 4.14.18, 4.15.14
cephadm-ansible (Red Hat package) - update to 4.1.4-1.el9cp
podman (Red Hat package) - addressed in versions 4.4.1-13.rhaos4.13.el8, 4.4.1-14.rhaos4.13.el9, 4.4.1-19.rhaos4.14.el8, 4.4.1-19.rhaos4.14.el9, 4.4.1-30.rhaos4.15.el8, 4.4.1-30.rhaos4.15.el9
openshift-ansible (Red Hat package) - addressed in versions 4.14.0-202409061409.p0.g846e89b.assembly.stream.el8, 4.14.0-202409061409.p0.g846e89b.assembly.stream.el9
kernel (Red Hat package) - addressed in versions 5.14.0-284.86.1.el9_2, 5.14.0-284.88.1.el9_2, 5.14.0-427.37.1.el9_4
kernel-rt (Red Hat package) - addressed in versions 5.14.0-284.86.1.rt14.371.el9_2, 5.14.0-284.88.1.rt14.373.el9_2
Red Hat Ceph Storage - addressed in versions 7.1, 8.1
openstack-ironic-python-agent (Red Hat package) - update to 9.3.1-0.20240911165036.dfceb59.el9
Oracle Solaris - update to 11.4 SRU 74
Red Hat OpenStack - addressed in versions 17.1.4, 18.0
ceph (Red Hat package) - addressed in versions 18.2.1-329.el8cp, 18.2.1-329.el9cp, 19.2.1-222.el9cp
openstack-ironic (Red Hat package) - update to 21.3.1-0.20240911165036.c0d61d0.el9
External References
Related Security Bulletins
- Open redirect in Pylons WebOb
- Fedora 42 update for python-webob
- Fedora 41 update for python-webob
- Fedora EPEL 8 update for python-webob
- Fedora EPEL 9 update for python-webob
- Fedora 39 update for python-webob
- Fedora 40 update for python-webob
- Fedora 40 update for python-webob
- Fedora 39 update for python-webob
- Fedora EPEL 9 update for python-webob
- Fedora EPEL 8 update for python-webob
- SUSE update for python-WebOb
- SUSE update for python-WebOb
- openEuler update for python-webob
- Ubuntu update for python-webob
- SUSE update for python-WebOb
- Open redirect in Red Hat OpenStack 18.0 packages
- Open redirect in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15 packages
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Oracle Solaris update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Open redirect in Red Hat OpenStack 17.1
- Open redirect in Red Hat OpenStack 17.1
- Anolis OS update for python-webob
- Multiple vulnerabilities in Red Hat Ceph Storage 7
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage)
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.15
- Multiple vulnerabilities in OpenShift Data Foundation (formerly OpenShift Container Storage) 4.14
- Multiple vulnerabilities in Red Hat Ceph Storage 8
- IBM Storage Ceph update for WebOb
- Fedora EPEL 10.3 update for python-webob
- Fedora 43 update for python-webob
- Fedora EPEL 9 update for python-webob
- Fedora EPEL 8 update for python-webob
- Fedora 44 update for FEDORA
- Fedora 43 update for FEDORA
- Fedora 44 update for python-webob