CVE-2017-1002150
Summary
| CVE | CVE-2017-1002150 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-14 13:29:00 UTC |
| Updated | 2022-12-21 15:01:00 UTC |
| Description | python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| github.com/fedora-infra/python-fedora/commit/b27f38a67573f4c989710c9bfb7... |
MISC |
github.com |
Patch, Third Party Advisory |
| Disable covert redirects and CSRF token leaking · fedora-infra/python-fedora@b27f38a · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983498 Python (pip) Security Update for python-fedora (GHSA-m242-wc86-8768)