Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 43 python-scitokens Advisory 2026-727b73bfa0 Path Traversal Fix

fedora
Calendar Grey March 22, 2026
Dist Fedora Esm H88
Upgrade python-scitokens on Fedora to address legacy chaining, path traversal risks, and SQL injection issues in key handling.
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Cl...

Summary

SciToken reference implementation library

Update Information:

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens Fix SQL injection risk in KeyCache by using parameterized SQLite queries Prevent sibling-path authorization bypass in Enforcer scope checks

Change Log

* Fri Mar 13 2026 Derek Weitzel - 1.9.7-1 - Remove legacy parent SciToken chaining behavior from token initialization and claim handling - Harden Enforcer scope path traversal validation (including encoded traversal checks) - Clean up documentation references to parent/chained SciTokens * Fri Mar 13 2026 Derek Weitzel - 1.9.6-1 - Fix SQL injection risk in KeyCache by using parameterized SQLite queries - Prevent sibling-path authorization bypass in Enforcer scope checks * Sat Jan 17 2026 Fedora Release Engineering - 1.9.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References

Fedora Update Notification FEDORA-2026-727b73bfa0 2026-03-22 00:52:45.125293+00:00 Name : python-scitokens Product : Fedora 43 Version : 1.9.7 Release : 1.fc43 URL : https://scitokens.org Summary : SciToken reference implementation library Description : SciToken reference implementation library

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-727b73bfa0' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-scitokens
Product: Fedora 43
Version: 1.9.7
Release: 1.fc43
Summary: SciToken reference implementation library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here