A vulnerability in the Python infrastructure allowed spoofing of release links on python.org.
The Python Software Foundation disclosed a critical vulnerability in the release management API that could be exploited to attack the Python project's infrastructure. The vulnerability allowed attackers to bypass authentication and connect to the release management API with administrator privileges by sending a request with any key and specifying one of the administrators in the username field. The resulting […]
