RHBA-2024:1420MediumCVSS 4.2
Red Hat Bug Fix Advisory: resource-agents update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-45803 — urllib3: Request body not stripped after redirect from 303 status changes request method to GET
🎯 Affected products38
- Red Hat Enterprise Linux High Availability EUS (v.8.8)
- Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-0:4.9.0-40.el8_8.2.aarch64 as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-0:4.9.0-40.el8_8.2.ppc64le as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-0:4.9.0-40.el8_8.2.ppc64le as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-0:4.9.0-40.el8_8.2.s390x as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-0:4.9.0-40.el8_8.2.s390x as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-0:4.9.0-40.el8_8.2.src as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-0:4.9.0-40.el8_8.2.src as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-aliyun-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-aliyun-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-aliyun-debuginfo-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-aliyun-debuginfo-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-debuginfo-0:4.9.0-40.el8_8.2.aarch64 as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-debuginfo-0:4.9.0-40.el8_8.2.ppc64le as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-debuginfo-0:4.9.0-40.el8_8.2.ppc64le as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-debuginfo-0:4.9.0-40.el8_8.2.s390x as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-debuginfo-0:4.9.0-40.el8_8.2.s390x as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-debuginfo-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-debuginfo-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-debugsource-0:4.9.0-40.el8_8.2.aarch64 as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-debugsource-0:4.9.0-40.el8_8.2.ppc64le as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-debugsource-0:4.9.0-40.el8_8.2.ppc64le as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-debugsource-0:4.9.0-40.el8_8.2.s390x as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-debugsource-0:4.9.0-40.el8_8.2.s390x as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-debugsource-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- resource-agents-debugsource-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux Resilient Storage EUS (v.8.8)
- resource-agents-gcp-0:4.9.0-40.el8_8.2.x86_64 as a component of Red Hat Enterprise Linux High Availability EUS (v.8.8)
- +8 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Users unable to update should disable redirects for services that aren't expecting to respond with redirects with `redirects=False`, disable automatic redirects with `redirects=False`, and handle 301, 302, and 303 redirects manually by stripping the HTTP request body.