GHSA-m242-wc86-8768

Suggest an improvement
Source
https://github.com/advisories/GHSA-m242-wc86-8768
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-m242-wc86-8768/GHSA-m242-wc86-8768.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m242-wc86-8768
Aliases
Published
2018-07-13T15:17:05Z
Modified
2023-11-08T03:58:48.251362Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
python-fedora vulnerable to an open redirect resulting in loss of CSRF protection
Details

python-fedora 0.8.0 and lower is vulnerable to an open redirect, resulting in loss of CSRF protection.

References

Affected packages

PyPI / python-fedora

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.0

Affected versions

0.*

0.3.10
0.3.11
0.3.16
0.3.20
0.3.21a1
0.3.21
0.3.22
0.3.24
0.3.25
0.3.25.1
0.3.26
0.3.27
0.3.28
0.3.28.1
0.3.29
0.3.30
0.3.31
0.3.32.1
0.3.32.2
0.3.32.3
0.3.33
0.3.34
0.3.35
0.3.36
0.4.0
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.7.0
0.7.1
0.8.0