PT-2020-7856 · Jinja+1 · Jinja+1

Michael Scherer

·

Published

2020-02-17

·

Updated

2024-08-06

·

CVE-2015-5215

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Ipsilon versions 0.1.0 through 1.0.0
Description: The default configuration of the Jinja templating engine in the Identity Provider (IdP) server does not enable auto-escaping, making it easier for remote attackers to conduct cross-site scripting (XSS) attacks via template variables.
Recommendations: For Ipsilon versions 0.1.0 through 1.0.0, consider enabling auto-escaping in the Jinja templating engine configuration to mitigate the risk of cross-site scripting (XSS) attacks.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2015-5215

Affected Products

Ipsilon
Jinja