[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250039

 
 

909

 
 

195882

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2024-2436 --- python-jinja2

ID: oval:org.secpod.oval:def:1702087Date: (C)2024-02-28   (M)2024-02-28
Class: PATCHFamily: unix




Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting . The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based

Platform:
Amazon Linux 2
Product:
python-jinja2
Reference:
ALAS2-2024-2436
CVE-2024-22195
CVE    1
CVE-2024-22195
CPE    2
cpe:/o:amazon:linux:2
cpe:/a:pocoo:python_jinja2

© SecPod Technologies