CVE-2023-41419
Summary
| CVE | CVE-2023-41419 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-25 12:15:00 UTC |
| Updated | 2023-10-17 00:15:00 UTC |
| Description | An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| gevent.pywsgi: Much improved handling of chunk trailers. · gevent/gevent@2f53c85 · GitHub | MISC | github.com | |
| Vulnerability in gevent.pywsgi.WSGIServer · Issue #1989 · gevent/gevent · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 242505 Red Hat Update for OpenStack Platform 17.1.1 (RHSA-2023:7438)
- 755097 SUSE Enterprise Linux Security Update for python-gevent (SUSE-SU-2023:4091-1)
- 907532 Common Base Linux Mariner (CBL-Mariner) Security Update for python-gevent (30058-1)
- 995407 Python (Pip) Security Update for gevent (GHSA-x7m3-jprg-wc5g)