Description
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: Low
Affected Packages2 packages
Also affects: Openshift Container Platform 4.12
🔴Vulnerability Details
2CVEListPython-eventlet: patch regression for cve-2021-21419 in some red hat builds↗2023-11-01 ▶ GHSAGHSA-326p-894x-j8c7: A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-20↗2023-11-01 ▶ 📋Vendor Advisories
2Red Hatpython-eventlet: patch regression for CVE-2021-21419 in some Red Hat builds↗2023-10-17 ▶ DebianCVE-2023-5625: python-eventlet - A regression was introduced in the Red Hat build of python-eventlet due to a cha...↗2023 ▶