Candidate: CVE-2017-1002150 PublicDate: 2017-09-14 13:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1002150 Description: python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_python-fedora: other: https://github.com/fedora-infra/python-fedora/commit/b27f38a67573f4c989710c9bfb726dd4c1eeb929 upstream_python-fedora: released (0.9.0-1) precise/esm_python-fedora: DNE trusty_python-fedora: DNE trusty/esm_python-fedora: DNE vivid/ubuntu-core_python-fedora: DNE xenial_python-fedora: ignored (end of standard support, was needed) zesty_python-fedora: ignored (reached end-of-life) artful_python-fedora: not-affected (0.9.0-1) bionic_python-fedora: not-affected (0.9.0-1) cosmic_python-fedora: not-affected (0.9.0-1) disco_python-fedora: not-affected (0.9.0-1) eoan_python-fedora: not-affected (0.9.0-1) focal_python-fedora: not-affected (0.9.0-1) groovy_python-fedora: not-affected (0.9.0-1) hirsute_python-fedora: not-affected (0.9.0-1) impish_python-fedora: not-affected (0.9.0-1) jammy_python-fedora: not-affected (0.9.0-1) devel_python-fedora: not-affected (0.9.0-1)