Red Hat Security Advisory: Red Hat Ceph Storage 7.1 security, bug fix, and enhancement updates
🔗 CVE IDs covered (9)
📋 Description
CVE-2023-23934 — python-werkzeug: cookie prefixed with = can shadow unprefixed cookie CVE-2023-25577 — python-werkzeug: high resource usage when parsing multipart form data with many fields CVE-2023-46446 — python-asyncssh: Rogue Session Attack CVE-2023-48795 — ssh: Prefix truncation attack on Binary Packet Protocol (BPP) CVE-2024-24790 — golang: net/netip: Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses CVE-2024-34069 — python-werkzeug: user may execute code on a developer's machine CVE-2024-42353 — webob: WebOb's location header normalization during redirect leads to open redirect CVE-2024-47191 — oath-toolkit: Local root exploit in a PAM module CVE-2024-48916 — ceph: rhceph-container: Authentication bypass in CEPH RadosGW
🔗 References (28)
- selfhttps://access.redhat.com/errata/RHSA-2025:4664
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2252788
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270948
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284356
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2312113
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2314387
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315596
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2315885
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2321291
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348763
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348935
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348945
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348968
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348970
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2349078
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2349723
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2351271
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2351465
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2352965
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2356050
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2356542
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2357889
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2358123
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2358562
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2360911
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2362258
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_4664.json