FS#70041 - [python-flask-security-too] [Security] cross-site request forgery (CVE-2021-21241)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Wednesday, 17 March 2021, 11:44 GMT
Last edited by Jonas Witschel (diabonas) - Tuesday, 18 May 2021, 06:55 GMT
Opened by Jonas Witschel (diabonas) - Wednesday, 17 March 2021, 11:44 GMT
Last edited by Jonas Witschel (diabonas) - Tuesday, 18 May 2021, 06:55 GMT
|
Details
Summary
======= The package python-flask-security-too is vulnerable to cross-site request forgery via CVE-2021-21241. Guidance ======== Upgrading python-flask-security-too to at least version 3.4.5 (the latest version is 4.0.0 at the moment) fixes the issue. References ========== https://security.archlinux.org/AVG-1434 https://github.com/Flask-Middleware/flask-security/security/advisories/GHSA-hh7m-rx4f-4vpv https://github.com/Flask-Middleware/flask-security/issues/421 https://github.com/Flask-Middleware/flask-security/commit/61d313150b5f620d0b800896c4f2199005e84b1f |
This task depends upon
Closed by Jonas Witschel (diabonas)
Tuesday, 18 May 2021, 06:55 GMT
Reason for closing: Fixed
Additional comments about closing: python-flask-security-too 4.0.1-1 in [community]
Tuesday, 18 May 2021, 06:55 GMT
Reason for closing: Fixed
Additional comments about closing: python-flask-security-too 4.0.1-1 in [community]