PT-2024-10415 · Jinja+10 · Jinja+10

Ry0Tak

·

Published

2023-01-16

·

Updated

2026-06-03

·

CVE-2024-34064

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jinja versions prior to 3.1.4
Description The issue is related to the xmlattr filter in Jinja, which accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, /, >, or =, as each would then be interpreted as starting a separate attribute. If an application accepts keys as user input and renders these in pages that other users see, an attacker could use this to inject other attributes and perform cross-site scripting (XSS). The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For versions prior to 3.1.4, update to version 3.1.4 or later to resolve the issue. As a temporary workaround, consider validating user input for the xmlattr filter to prevent injection of non-attribute characters. Restrict access to the xmlattr filter to minimize the risk of exploitation until the issue is resolved. Avoid using the xmlattr filter with unvalidated user input until the issue is resolved.

Exploit

Fix

Protection Mechanism Failure

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:3820
ALSA-2024:4231
ALSA-2024:9150
ALSA-2024_3820
ALSA-2024_4231
ALSA-2024_9150
ALT-PU-2025-3752
AZL-40369
AZL-40420
AZL-40439
AZL-40444
AZL-75801
BDU:2025-00112
BDU:2025-00113
BDU:2025-00945
CESA-2024_4231
CVE-2024-34064
DLA-3988-1
DLA-3988-2
GHSA-H75V-3VVJ-5MFJ
INFSA-2024_3820
INFSA-2024_4231
INFSA-2024_9150
MGASA-2024-0199
OESA-2024-1605
OPENSUSE-SU-2024:13930-1
OPENSUSE-SU-2024_1863-1
OPENSUSE-SU-2024_1864-1
RHSA-2024:3781
RHSA-2024:3795
RHSA-2024:3811
RHSA-2024:3820
RHSA-2024:4231
RHSA-2024:4404
RHSA-2024:4414
RHSA-2024:4427
RHSA-2024:4522
RHSA-2024:4616
RHSA-2024:4958
RHSA-2024:5662
RHSA-2024:5810
RHSA-2024:6011
RHSA-2024:9150
RHSA-2024_3820
RHSA-2024_4231
RHSA-2024_9150
RHSA-2025:1335
RLSA-2024:3820
RLSA-2024:4231
RLSA-2024:9150
SUSE-SU-2024:1863-1
SUSE-SU-2024:1863-2
SUSE-SU-2024:1864-1
SUSE-SU-2024:1948-1
SUSE-SU-2024_1948-1
SUSE-SU-2025:20035-1
USN-6787-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Jinja
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu