Описание
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| esm-apps/jammy | released | 3.1.7-1ubuntu0.1~esm1 |
| esm-apps/noble | released | 3.1.7-2ubuntu0.24.04.1 |
| esm-apps/resolute | released | 3.2.12-1ubuntu0.1~esm1 |
| jammy | needed | |
| noble | released | 3.1.7-2ubuntu0.24.04.1 |
| questing | released | 3.1.7-2ubuntu0.25.10.1 |
| resolute | needed | |
| upstream | released | 3.2.13 |
Показывать по
Ссылки на источники
EPSS
7.5 High
CVSS3
Связанные уязвимости
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.
dynaconf is a configuration management tool for Python. Prior to versi ...
dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver
EPSS
7.5 High
CVSS3