python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection
"https://github.com/pypa/advisory-database/blob/main/vulns/python-fedora/PYSEC-2017-27.yaml"