RHSA-2025:4664HighCVSS 9.1

Red Hat Security Advisory: Red Hat Ceph Storage 7.1 security, bug fix, and enhancement updates

Published
May 7, 2025
Last Modified
June 4, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2023-23934 — python-werkzeug: cookie prefixed with = can shadow unprefixed cookie CVE-2023-25577 — python-werkzeug: high resource usage when parsing multipart form data with many fields CVE-2023-46446 — python-asyncssh: Rogue Session Attack CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses CVE-2024-34069 — python-werkzeug: user may execute code on a developer's machine CVE-2024-42353 — webob: WebOb's location header normalization during redirect leads to open redirect CVE-2024-47191 — oath-toolkit: Local root exploit in a PAM module CVE-2024-48916 — ceph: rhceph-container: Authentication bypass in CEPH RadosGW

🔗 References (28)