RHSA-2019:1152-01 -- Redhat python-jinja2ID: oval:org.secpod.oval:def:66433 | Date: (C)2020-10-30 (M)2024-05-22 |
Class: PATCH | Family: unix |
The python-jinja2 package contains Jinja2, a template engine written in pure Python. Jinja2 provides a Django inspired non-XML syntax but supports inline expressions and an optional sandboxed environment. Security Fix: * python-jinja2: str.format_map allows sandbox escape For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.
Product: |
python-jinja2 |
python3-jinja2 |