2024-07-12 03:04:04 +00:00

100 lines
3.7 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20249139",
"Version": "oval:org.altlinux.errata:def:20249139",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2024-9139: package `python3-module-urllib3` update to version 1.26.17-alt0.p10.1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch c10f1"
],
"Products": [
"ALT SP Workstation",
"ALT SP Server"
]
}
],
"References": [
{
"RefID": "ALT-PU-2024-9139",
"RefURL": "https://errata.altlinux.org/ALT-PU-2024-9139",
"Source": "ALTPU"
},
{
"RefID": "BDU:2023-08730",
"RefURL": "https://bdu.fstec.ru/vul/2023-08730",
"Source": "BDU"
},
{
"RefID": "CVE-2023-43804",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-43804",
"Source": "CVE"
}
],
"Description": "This update upgrades python3-module-urllib3 to version 1.26.17-alt0.p10.1. \nSecurity Fix(es):\n\n * BDU:2023-08730: Уязвимость модуля urllib3 интерпретатора языка программирования Python, связанная с отсутствием защиты служебных данных, позволяющая нарушителю раскрыть защищаемую информацию\n\n * CVE-2023-43804: urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak information via HTTP redirects to a different origin if that user doesn't disable redirects explicitly. This issue has been patched in urllib3 version 1.26.17 or 2.0.5.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2024-07-11"
},
"Updated": {
"Date": "2024-07-11"
},
"BDUs": [
{
"ID": "BDU:2023-08730",
"CVSS": "AV:N/AC:L/Au:S/C:C/I:C/A:N",
"CVSS3": "AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-200",
"Href": "https://bdu.fstec.ru/vul/2023-08730",
"Impact": "High",
"Public": "20231104"
}
],
"CVEs": [
{
"ID": "CVE-2023-43804",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-200",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-43804",
"Impact": "High",
"Public": "20231004"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:spworkstation:10",
"cpe:/o:alt:spserver:10"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:4001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20249139001",
"Comment": "python3-module-urllib3 is earlier than 2:1.26.17-alt0.p10.1"
}
]
}
]
}
}
]
}