Hide Forgot
A possible information leak flaw was reported to the Full Disclosure mailing list: http://seclists.org/fulldisclosure/2013/Dec/145 No details are provided, and another flaw may be need to be used in conjunction in order to trigger the reported information leak. Regarding the other flaws in that post, based on the version numbers Fedora and EPEL would not be affected by the reported CSRF and DoS issues. Filing this (fairly useless) bug in case there is a version later than 3.8 we can upgrade to soon.
There have been other reports without the details: http://seclists.org/fulldisclosure/2013/Dec/46 Feel free to close not a bug as there is not much we can do at the moment.