Количество 47
Количество 47
RLSA-2024:2968
Moderate: fence-agents security and bug fix update
ELSA-2024-2968
ELSA-2024-2968: fence-agents security and bug fix update (MODERATE)
ELSA-2024-2132
ELSA-2024-2132: fence-agents security and bug fix update (MODERATE)
CVE-2024-22195
Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.
CVE-2024-22195
Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.
CVE-2024-22195
Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.
CVE-2024-22195
Jinja vulnerable to Cross-Site Scripting (XSS)
CVE-2024-22195
Jinja is an extensible templating engine. Special placeholders in the ...
RLSA-2024:3102
Moderate: python-jinja2 security update
GHSA-h5c8-rqwp-cp95
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
ELSA-2024-3102
ELSA-2024-3102: python-jinja2 security update (MODERATE)
ELSA-2024-2348
ELSA-2024-2348: python-jinja2 security update (MODERATE)
BDU:2024-00884
Уязвимость фильтра xmlattr шаблонизатора Jinja2 для языка программирования Python, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)
SUSE-SU-2024:1864-1
Security update for python-Jinja2
SUSE-SU-2024:1863-1
Security update for python-Jinja2
ROS-20240902-04
Уязвимость python3-jinja2
CVE-2023-52323
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
CVE-2023-52323
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
CVE-2023-52323
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack.
CVE-2023-52323
PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakag ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2024:2968 Moderate: fence-agents security and bug fix update | около 2 лет назад | |||
ELSA-2024-2968 ELSA-2024-2968: fence-agents security and bug fix update (MODERATE) | около 2 лет назад | |||
ELSA-2024-2132 ELSA-2024-2132: fence-agents security and bug fix update (MODERATE) | больше 2 лет назад | |||
CVE-2024-22195 Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based. | CVSS3: 5.4 | 1% Низкий | больше 2 лет назад | |
CVE-2024-22195 Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based. | CVSS3: 5.4 | 1% Низкий | больше 2 лет назад | |
CVE-2024-22195 Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based. | CVSS3: 5.4 | 1% Низкий | больше 2 лет назад | |
CVE-2024-22195 Jinja vulnerable to Cross-Site Scripting (XSS) | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
CVE-2024-22195 Jinja is an extensible templating engine. Special placeholders in the ... | CVSS3: 5.4 | 1% Низкий | больше 2 лет назад | |
RLSA-2024:3102 Moderate: python-jinja2 security update | 1% Низкий | около 2 лет назад | ||
GHSA-h5c8-rqwp-cp95 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter | CVSS3: 5.4 | 1% Низкий | больше 2 лет назад | |
ELSA-2024-3102 ELSA-2024-3102: python-jinja2 security update (MODERATE) | 1% Низкий | около 2 лет назад | ||
ELSA-2024-2348 ELSA-2024-2348: python-jinja2 security update (MODERATE) | 1% Низкий | больше 2 лет назад | ||
BDU:2024-00884 Уязвимость фильтра xmlattr шаблонизатора Jinja2 для языка программирования Python, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS) | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
SUSE-SU-2024:1864-1 Security update for python-Jinja2 | около 2 лет назад | |||
SUSE-SU-2024:1863-1 Security update for python-Jinja2 | около 2 лет назад | |||
ROS-20240902-04 Уязвимость python3-jinja2 | CVSS3: 6.1 | 1% Низкий | почти 2 года назад | |
CVE-2023-52323 PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад | |
CVE-2023-52323 PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад | |
CVE-2023-52323 PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakage for OAEP decryption, exploitable for a Manger attack. | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад | |
CVE-2023-52323 PyCryptodome and pycryptodomex before 3.19.1 allow side-channel leakag ... | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу