Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 44 python-scitokens Important Path Checks Fix 2026-86ad7d8a1a

fedora
Calendar Grey March 22, 2026
Dist Fedora Esm H88
Critical security update for Fedora 44 python-scitokens, protecting against SQL injection and path traversal risks.
Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Cl...

Summary

SciToken reference implementation library

Update Information:

Remove legacy parent SciToken chaining behavior from token initialization and claim handling Harden Enforcer scope path traversal validation (including encoded traversal checks) Clean up documentation references to parent/chained SciTokens Fix SQL injection risk in KeyCache by using parameterized SQLite queries Prevent sibling-path authorization bypass in Enforcer scope checks

Change Log

* Fri Mar 13 2026 Derek Weitzel - 1.9.7-1 - Remove legacy parent SciToken chaining behavior from token initialization and claim handling - Harden Enforcer scope path traversal validation (including encoded traversal checks) - Clean up documentation references to parent/chained SciTokens * Fri Mar 13 2026 Derek Weitzel - 1.9.6-1 - Fix SQL injection risk in KeyCache by using parameterized SQLite queries - Prevent sibling-path authorization bypass in Enforcer scope checks

References

Fedora Update Notification FEDORA-2026-86ad7d8a1a 2026-03-22 00:15:14.987315+00:00 Name : python-scitokens Product : Fedora 44 Version : 1.9.7 Release : 1.fc44 URL : https://scitokens.org Summary : SciToken reference implementation library Description : SciToken reference implementation library

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-86ad7d8a1a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-scitokens
Product: Fedora 44
Version: 1.9.7
Release: 1.fc44
Summary: SciToken reference implementation library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here