PT-2019-7543 · Pallets+4 · Jinja+4

Olivier Dony

·

Publicado

2019-04-08

·

Atualizado

2024-06-15

·

CVE-2016-10745

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pallets Jinja versions prior to 2.8.1
Description The issue allows a sandbox escape through the str.format function.
Recommendations For versions prior to 2.8.1, update to version 2.8.1 or later to resolve the issue.

Correção

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2019_1022
CVE-2016-10745
GHSA-HJ2J-77XM-MC5V
MGASA-2019-0177
OPENSUSE-SU-2019:1395-1
OPENSUSE-SU-2019_1395-1
OPENSUSE-SU-2019_1614-1
OPENSUSE-SU-2024:11208-1
OPENSUSE-SU-2024:13930-1
PYSEC-2019-220
RHSA-2019:1022
RHSA-2019:1237
RHSA-2019:1260
RHSA-2019:3172
RHSA-2019:3964
RHSA-2019:4062
RHSA-2019_1022
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2019:1156-1
SUSE-SU-2019:1323-1
SUSE-SU-2019:1554-1
SUSE-SU-2019_1156-1
SUSE-SU-2019_1323-1
SUSE-SU-2020:3897-1
USN-4011-1
USN-4011-2

Produtos afetados

Centos
Jinja
Red Hat
Suse
Ubuntu