Package
openstack-placement-2025.1-fips
Component
oslo-messaging
Latest update
7.4
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Previous location
/opt/chainguard/openstack-placement-2025.1/lib/python3.12/site-packages/oslo_messaging-16.1.1.dist-info/METADATANew location
/opt/chainguard/openstack-placement-2025.1/lib/python3.12/site-packages/oslo_messaging-16.1.2.dist-info/METADATAImpact
version-only path change detected during APK rebuild
Status
Impact
The vulnerable component is the Python package oslo-messaging (OpenStack oslo.messaging). Per the GitHub Security Advisory at https://github.com/advisories/GHSA-76qh-xr7q-h39m, there is no patched version for oslo-messaging (vulnerable range >=1.0.0,<=17.3.0). Upstream OpenStack oslo.messaging maintainers will need to release a fixed version of oslo-messaging in order to resolve this CVE.
Status