Описание
Important: python-jinja2 security update
The python-jinja2 package contains Jinja2, a template engine written in pure Python. Jinja2 provides a Django inspired non-XML syntax but supports inline expressions and an optional sandboxed environment.
Security Fix(es):
- python-jinja2: str.format_map allows sandbox escape (CVE-2019-10906)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Затронутые продукты
Rocky Linux 8
Связанные CVE
Исправления
- Red Hat - 1698839
Связанные уязвимости
CVSS3: 8.6
ubuntu
больше 6 лет назад
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
CVSS3: 9
redhat
больше 6 лет назад
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
CVSS3: 8.6
nvd
больше 6 лет назад
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
CVSS3: 8.6
debian
больше 6 лет назад
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape ...