An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-python3-gevent | Nov 7, 2024 | Sep 25, 2023 | |
| Debian | debian-upgrade-python-gevent | Nov 26, 2025 | Nov 26, 2025 | |
| Oracle_linux | — | oracle-linux-upgrade-python3-gevent | Nov 11, 2024 | Aug 31, 2023 |
| Redhat_linux | redhat-upgrade-python-gevent-debugsourceredhat-upgrade-python3-geventredhat-upgrade-python3-gevent-debuginfo | Oct 16, 2024 | Sep 25, 2023 | |
| Rocky_linux | rocky-upgrade-python-gevent-debugsourcerocky-upgrade-python3-geventrocky-upgrade-python3-gevent-debuginfo | Jun 1, 2026 | May 29, 2026 | |
| Suse | — | suse-upgrade-python-gevent-docsuse-upgrade-python2-geventsuse-upgrade-python3-gevent | Oct 18, 2023 | Sep 25, 2023 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Sep 25, 2023 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Sep 25, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub