Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Fedora 42 python-scitokens Path Traversal SQL Fix FEDORA-2026-dec8f790f7

fedora
Calendar Grey March 22, 2026
Dist Fedora Esm H88
Upgrade python-scitokens in Fedora 42 to address path traversal and SQL injection risks effectively.
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Cl...

Summary

SciToken reference implementation library

Update Information:

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens Fix SQL injection risk in KeyCache by using parameterized SQLite queries Prevent sibling-path authorization bypass in Enforcer scope checks

Change Log

* Fri Mar 13 2026 Derek Weitzel - 1.9.7-1 - Remove legacy parent SciToken chaining behavior from token initialization and claim handling - Harden Enforcer scope path traversal validation (including encoded traversal checks) - Clean up documentation references to parent/chained SciTokens * Fri Mar 13 2026 Derek Weitzel - 1.9.6-1 - Fix SQL injection risk in KeyCache by using parameterized SQLite queries - Prevent sibling-path authorization bypass in Enforcer scope checks * Sat Jan 17 2026 Fedora Release Engineering - 1.9.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

References

Fedora Update Notification FEDORA-2026-dec8f790f7 2026-03-22 01:07:57.226580+00:00 Name : python-scitokens Product : Fedora 42 Version : 1.9.7 Release : 1.fc42 URL : https://scitokens.org Summary : SciToken reference implementation library Description : SciToken reference implementation library

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-dec8f790f7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-scitokens
Product: Fedora 42
Version: 1.9.7
Release: 1.fc42
Summary: SciToken reference implementation library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here