Linuxsecurity Fedora Python SciTokens Vulnerabilities Addressed in Recent Updates
Article Content
- •Fedora released critical updates for python-scitokens on March 22, 2026.
- •Vulnerabilities addressed include SQL injection and path traversal issues.
- •Users are urged to update to version 1.9.7 using the 'dnf' package manager.
On March 22, 2026, Fedora released updates for the python-scitokens library addressing several vulnerabilities. The updates include the removal of legacy parent SciToken chaining behavior, enhancements to path traversal validation, and fixes for SQL injection risks in KeyCache through parameterized queries. These vulnerabilities could potentially allow unauthorized access and data manipulation. The updates affect Fedora 42 and Fedora 43 users, with versions 1.9.7 being the latest. Users are advised to apply the updates using the 'dnf' package manager. The updates were made available following the identification of risks associated with sibling-path authorization bypass and SQL injection. The updates are critical for maintaining the security of systems utilizing the SciToken library. No active exploitation has been reported at this time.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…