Description
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
References (11)
Core 11
Core References
Vendor Advisory x_refsource_misc
https://palletsprojects.com/blog/jinja-281-released/
Patch, Third Party Advisory x_refsource_misc
https://github.com/pallets/jinja/commit/9b53045c34e61013dc8f09b7e52a555fa16bed16
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1022
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1237
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:1260
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/4011-1/
Vendor Advisory vendor-advisory
x_refsource_ubuntu
https://usn.ubuntu.com/4011-2/
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:3964
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2019:4062
Scores
CVSS v3
8.6
EPSS
0.0349
EPSS Percentile
87.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Details
CWE
CWE-134
Status
published
Products (2)
palletsprojects/jinja
< 2.8.1
pypi/Jinja2
0 - 2.8.1PyPI
Published
Apr 08, 2019
Tracked Since
Feb 18, 2026