RHSA-2022:1764MediumCVSS 8.8
Red Hat Security Advisory: python38:3.8 and python38-devel:3.8 security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2021-3733 — python: urllib: Regular expression DoS in AbstractBasicAuthHandler CVE-2021-3737 — python: urllib: HTTP client possible infinite loop on a 100 Continue response CVE-2021-43818 — python-lxml: HTML Cleaner allows crafted and SVG embedded scripts to pass through CVE-2022-0391 — python: urllib.parse does not sanitize URLs containing ASCII newline and tabs
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2022:1764
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.6_release_notes/
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995162
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1995234
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2004587
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2006789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2032569
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2047376
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1764.json