—
PYSEC-2017-13
Quick fix
PYSEC-2017-13 — fedmsg: upgrade to the fixed version with the command below.
pip install --upgrade 'fedmsg>=0.18.2'Details
FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.
Are you affected?
Enter the version of the package you're using.