More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2315806 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Fixed in pagure 5.14.x with commit https://pagure.io/pagure/c/9b715170008bdc1dd273f7c28debe782a8f7969e?branch=5.14.x Current package version in Fedora and EPEL (https://src.fedoraproject.org/rpms/pagure) is pagure-5.14.1 No further action required in my opinion, the CVE assignment just came with a delay
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.