Описание
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.
A flaw was found in dynaconf, a Python configuration management tool. This Server-Side Template Injection (SSTI) vulnerability occurs due to unsafe template evaluation in the @Jinja resolver when the jinja2 package is installed. A remote attacker could exploit this by embedding malicious template expressions in configuration values, which are then processed without a sandboxed environment. This could lead to arbitrary code execution on the affected system.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/hub-rhel9 | Affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-26/lightspeed-rhel9 | Affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform/automation-dashboard-rhel9 | Affected | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-tech-preview/automation-dashboard-rhel9 | Will not fix | ||
| Red Hat Ansible Automation Platform 2.6 for RHEL 9 | automation-controller | Fixed | RHSA-2026:34160 | 01.07.2026 |
| Red Hat Ansible Automation Platform 2.5 | ansible-automation-platform-25/lightspeed-rhel8 | Fixed | RHSA-2026:13553 | 04.05.2026 |
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/eda-controller-rhel9 | Fixed | RHSA-2026:13545 | 04.05.2026 |
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/gateway-rhel9 | Fixed | RHSA-2026:13545 | 04.05.2026 |
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/controller-rhel9 | Fixed | RHSA-2026:24866 | 09.06.2026 |
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/controller-rhel9 | Fixed | RHSA-2026:34374 | 01.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.
dynaconf is a configuration management tool for Python. Prior to versi ...
dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver
EPSS
7.5 High
CVSS3