RHSA-2025:1335
Advisory lineage Upstream: 13 Downstream: 0
Published: 12 Feb 2025, 10:04
Last modified:03 Jun 2026, 10:11
Vulnerability Summary
Overall Risk (default)
medium
30/100 CVSS Score
7.5 HIGH
3.1 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
12 Feb 2025, 10:04
Published
Vulnerability first disclosed
03 Jun 2026, 10:11
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: RHUI 4.11 security, bugfix, and enhancement update
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Systems
- redhat•python-aiohttp
< 0:3.9.4-1.el8ui
- redhat•python-aiohttp-debugsource
< 0:3.9.4-1.el8ui
- redhat•python-cryptography
< 0:42.0.8-1.el8ui
- redhat•python-cryptography-debugsource
< 0:42.0.8-1.el8ui
- redhat•python-django
< 0:4.2.15-1.el8ui
- redhat•python-grpcio
< 0:1.65.4-1.el8ui
- redhat•python-grpcio-debugsource
< 0:1.65.4-1.el8ui
- redhat•python-gunicorn
< 0:22.0.0-1.0.1.el8ui
- redhat•python-jinja2
< 0:3.1.4-1.el8ui
- redhat•python-requests
< 0:2.32.3-2.el8ui
- redhat•python-sqlparse
< 0:0.5.0-1.el8ui
- redhat•python3.11-aiohttp
< 0:3.9.4-1.el8ui
- redhat•python3.11-aiohttp-debuginfo
< 0:3.9.4-1.el8ui
- redhat•python3.11-cryptography
< 0:42.0.8-1.el8ui
- redhat•python3.11-cryptography-debuginfo
< 0:42.0.8-1.el8ui
- redhat•python3.11-django
< 0:4.2.15-1.el8ui
- redhat•python3.11-grpcio
< 0:1.65.4-1.el8ui
- redhat•python3.11-grpcio-debuginfo
< 0:1.65.4-1.el8ui
- redhat•python3.11-gunicorn
< 0:22.0.0-1.0.1.el8ui
- redhat•python3.11-jinja2
< 0:3.1.4-1.el8ui
- redhat•python3.11-requests
< 0:2.32.3-2.el8ui
- redhat•python3.11-sqlparse
< 0:0.5.0-1.el8ui
References (69)
- https://access.redhat.com/errata/RHSA-2025:1335
- https://access.redhat.com/security/updates/classification/#important
- https://docs.redhat.com/en/documentation/red_hat_update_infrastructure/4/html/release_notes/index
- https://bugzilla.redhat.com/show_bug.cgi?id=2269617
- https://bugzilla.redhat.com/show_bug.cgi?id=2275280
- https://bugzilla.redhat.com/show_bug.cgi?id=2275989
- https://bugzilla.redhat.com/show_bug.cgi?id=2278038
- https://bugzilla.redhat.com/show_bug.cgi?id=2278710
- https://bugzilla.redhat.com/show_bug.cgi?id=2279476
- https://bugzilla.redhat.com/show_bug.cgi?id=2282114
- https://bugzilla.redhat.com/show_bug.cgi?id=2295938
- https://bugzilla.redhat.com/show_bug.cgi?id=2302433
- https://bugzilla.redhat.com/show_bug.cgi?id=2302434
- https://bugzilla.redhat.com/show_bug.cgi?id=2302435
- https://bugzilla.redhat.com/show_bug.cgi?id=2302436
- https://issues.redhat.com/browse/RHUI-429
- https://issues.redhat.com/browse/RHUI-577
- https://issues.redhat.com/browse/RHUI-617
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1335.json
- https://access.redhat.com/security/cve/CVE-2024-1135
- https://www.cve.org/CVERecord?id=CVE-2024-1135
- https://nvd.nist.gov/vuln/detail/CVE-2024-1135
- https://github.com/advisories/GHSA-w3h3-4rj7-4ph4
- https://github.com/benoitc/gunicorn/commit/ac29c9b0a758d21f1e0fb3b3457239e523fa9f1d
- https://huntr.com/bounties/22158e34-cfd5-41ad-97e0-a780773d96c1
- https://access.redhat.com/security/cve/CVE-2024-4340
- https://www.cve.org/CVERecord?id=CVE-2024-4340
- https://nvd.nist.gov/vuln/detail/CVE-2024-4340
- https://github.com/advisories/GHSA-2m57-hf25-phgg
- https://access.redhat.com/security/cve/CVE-2024-7246
- https://bugzilla.redhat.com/show_bug.cgi?id=2303104
- https://www.cve.org/CVERecord?id=CVE-2024-7246
- https://nvd.nist.gov/vuln/detail/CVE-2024-7246
- https://github.com/grpc/grpc/issues/36245
- https://access.redhat.com/security/cve/CVE-2024-26130
- https://www.cve.org/CVERecord?id=CVE-2024-26130
- https://nvd.nist.gov/vuln/detail/CVE-2024-26130
- https://access.redhat.com/security/cve/CVE-2024-27306
- https://www.cve.org/CVERecord?id=CVE-2024-27306
- https://nvd.nist.gov/vuln/detail/CVE-2024-27306
- https://access.redhat.com/security/cve/CVE-2024-30251
- https://www.cve.org/CVERecord?id=CVE-2024-30251
- https://nvd.nist.gov/vuln/detail/CVE-2024-30251
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-5m98-qgg9-wh84
- https://www.openwall.com/lists/oss-security/2024/05/02/4
- https://access.redhat.com/security/cve/CVE-2024-34064
- https://www.cve.org/CVERecord?id=CVE-2024-34064
- https://nvd.nist.gov/vuln/detail/CVE-2024-34064
- https://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfj
- https://access.redhat.com/security/cve/CVE-2024-35195
- https://www.cve.org/CVERecord?id=CVE-2024-35195
- https://nvd.nist.gov/vuln/detail/CVE-2024-35195
- https://github.com/psf/requests/security/advisories/GHSA-9wx4-h78v-vm56
- https://access.redhat.com/security/cve/CVE-2024-39614
- https://www.cve.org/CVERecord?id=CVE-2024-39614
- https://nvd.nist.gov/vuln/detail/CVE-2024-39614
- https://access.redhat.com/security/cve/CVE-2024-41989
- https://www.cve.org/CVERecord?id=CVE-2024-41989
- https://nvd.nist.gov/vuln/detail/CVE-2024-41989
- https://access.redhat.com/security/cve/CVE-2024-41990
- https://www.cve.org/CVERecord?id=CVE-2024-41990
- https://nvd.nist.gov/vuln/detail/CVE-2024-41990
- https://www.djangoproject.com/weblog/2024/aug/06/security-releases/
- https://access.redhat.com/security/cve/CVE-2024-41991
- https://www.cve.org/CVERecord?id=CVE-2024-41991
- https://nvd.nist.gov/vuln/detail/CVE-2024-41991
- https://access.redhat.com/security/cve/CVE-2024-42005
- https://www.cve.org/CVERecord?id=CVE-2024-42005
- https://nvd.nist.gov/vuln/detail/CVE-2024-42005