The vendor explicitly identifies these products as affected by this CVE.
- python2-webob as a component of Red Hat Ceph Storage 4
- python3-webob as a component of Red Hat Ceph Storage 4
- python-webob.src as a component of Red Hat Ceph Storage 5
- python-webob.src as a component of Red Hat Ceph Storage 6
- python-webob.src as a component of Red Hat Enterprise Linux 6
- python-webob.src as a component of Red Hat Enterprise Linux 7
- python-webob.src as a component of Red Hat Openshift Container Storage 4
- python3-webob as a component of Red Hat OpenStack Platform 16.1
- python3-webob as a component of Red Hat OpenStack Platform 16.2
- quay/quay-rhel8 as a component of Red Hat Quay 3
- Summary
- A vulnerability was found in the WebOb package. WebOb normalizes the HTTP Location header using urlparse and urljoin. If the URL starts with //, urlparse treats the following part as the hostname, and replaces the original request's hostname. This issue, combined with user interaction, may become a vulnerability.
- Remediation
- Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 For supported configurations, refer to: https://access.redhat.com/articles/1548993
