More information about this security flaw is available in the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=2315805 Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Fixed in pagure 5.14.x with commit https://pagure.io/pagure/c/1db796dd0fa85c5f30f1e7123638e237f73bc92d?branch=5.14.x Current package version in Fedora and EPEL (https://src.fedoraproject.org/rpms/pagure) is pagure-5.14.1 No further action required in my opinion, the CVE assignment just came with a delay