FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.
{
"binaries": [
{
"binary_version": "0.9.3-2",
"binary_name": "fedmsg"
},
{
"binary_version": "0.9.3-2",
"binary_name": "fedmsg-gateway"
},
{
"binary_version": "0.9.3-2",
"binary_name": "fedmsg-hub"
},
{
"binary_version": "0.9.3-2",
"binary_name": "fedmsg-irc"
},
{
"binary_version": "0.9.3-2",
"binary_name": "fedmsg-relay"
},
{
"binary_version": "0.9.3-2",
"binary_name": "python-fedmsg"
}
]
}