File _patchinfo of Package patchinfo.25560
<patchinfo incident="25560"> <issue tracker="cve" id="2021-21241"/> <issue tracker="bnc" id="1181058">VUL-0: CVE-2021-21241: python-Flask-Security-Too: unprotected GET requests could lead to malicious party obtaining the authentication token</issue> <packager>mcepl</packager> <rating>important</rating> <category>security</category> <summary>Security update for python-Flask-Security-Too</summary> <description>This update for python-Flask-Security-Too fixes the following issues: - CVE-2021-21241: Fixed an issue where GET requests lacking CSRF protection to certain endpoints could return the user's authentication token (bsc#1181058). </description> </patchinfo>