In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
History
01 Mar 2023, 14:56
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:* cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:* cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
|
References | (SUSE) http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html - Mailing List, Third Party Advisory | |
References | (REDHAT) https://access.redhat.com/errata/RHSA-2019:1237 - Third Party Advisory | |
References | (UBUNTU) https://usn.ubuntu.com/4011-2/ - Third Party Advisory | |
References | (REDHAT) https://access.redhat.com/errata/RHSA-2019:1329 - Third Party Advisory | |
References | (UBUNTU) https://usn.ubuntu.com/4011-1/ - Third Party Advisory | |
References | (SUSE) http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html - Mailing List, Third Party Advisory |
Information
Published : 2019-04-07 00:29
Updated : 2024-02-04 20:20
NVD link : CVE-2019-10906
Mitre link : CVE-2019-10906
CVE.ORG link : CVE-2019-10906
JSON object : View
Products Affected
redhat
- software_collections
palletsprojects
- jinja
canonical
- ubuntu_linux
opensuse
- leap
fedoraproject
- fedora
CWE