Red Hat released the fence-agents update 4.2.1-129.el8_10.4 for Red Hat Enterprise Linux 8, remediating CVE-2024-6345 and CVE-2024-37891. The update applies across RHEL 8 systems using High Availability, Resilient Storage, and Extended Life Cycle variants on x86_64, ARM64, IBM Z, and IBM Power. Fence-agents provides remote power-management functions used by clusters to restart or isolate failed nodes, making timely patching important for environments that use these components.
CVE-2024-6345 is an important-severity flaw in PyPA setuptools' package_index download functions that can enable remote code execution when package URLs or index-derived download inputs are attacker-controlled; upstream setuptools 70.0 replaced shell-based Git cloning with argument-array subprocess execution. CVE-2024-37891 affects urllib3 and can expose Proxy-Authorization credentials when requests follow cross-origin redirects because the header is not reliably stripped. Red Hat backported fixes across supported products, so organizations should validate installed vendor package builds rather than relying only on upstream version comparisons.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
RHSA-2024:6765 remediated CVE-2024-37891 in python3x-urllib3 for Ansible Automation Platform 2.4 on RHEL 8 and python-urllib3 for the RHEL 9 offering.
Red Hat issued RHSA-2024:6311 to remediate CVE-2024-37891 in the RHEL 8 resource-agents package.
Red Hat issued RHSA-2024:5258 to remediate CVE-2024-37891 in the RHEL 8 container-tools:rhel8 package stream.
Red Hat issued RHEA-2024:4071 to fix CVE-2024-6345 in the rhdh/rhdh-hub-rhel9 component of Red Hat Developer Hub 1.2 on RHEL 9.
Red Hat issued RHSA-2024:8842 and RHSA-2024:8843 to remediate CVE-2024-37891 in RHEL 8 python3.12-urllib3 and python3.11-urllib3, respectively.
RHBA-2024:7523 fixed CVE-2024-37891 in the rhdh/rhdh-hub-rhel9 component of Red Hat Developer Hub 1.3 on RHEL 9.
Red Hat issued RHSA-2024:7312 to fix CVE-2024-37891 in Ansible Automation Platform 2.4 automation-controller packages for RHEL 8 and RHEL 9.
RHSA-2024:6662 fixed CVE-2024-6345 in the Red Hat Enterprise Linux 7 Extended Lifecycle Support python-setuptools package.
RHSA-2024:6661 fixed CVE-2024-6345 in the Red Hat Enterprise Linux 7 Extended Lifecycle Support python3-setuptools package.
Red Hat released fence-agents 4.2.1-129.el8_10.4 through RHSA-2024:6309, fixing CVE-2024-37891 and CVE-2024-6345 for applicable RHEL 8 variants.
RHSA-2024:5962 remediated CVE-2024-6345 in the RHEL 8 python39:3.9 and python39-devel:3.9 packages.
Red Hat issued RHSA-2024:5530, RHSA-2024:5531, and RHSA-2024:5532 to fix CVE-2024-6345 in RHEL 8 python-setuptools, python3.12-setuptools, and python3.11-setuptools packages.
The changelog for python3-setuptools-53.0.0-12.el9_4.1 recorded a security fix for CVE-2024-6345, delivered as a backport rather than an upstream version rebase.
A vulnerability in urllib3 was identified in which the Proxy-Authorization header may not be stripped during a cross-origin redirect, potentially exposing proxy authentication material.
Fedora published fixed python-setuptools packages for Fedora 40 (69.0.3-4.fc40) and Fedora 39 (67.7.2-8.fc39) to their stable repositories.
Setuptools 70.0 remediated CVE-2024-6345 by replacing shell-based git clone execution with an argument-array subprocess invocation.
PyPA setuptools through version 69.1.1 was identified as vulnerable to remote code execution when package_index download functions process attacker-controlled package URLs or other untrusted download inputs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.