Vulnerability Database
Blog
FAQ
Docs
PYSEC-2019-217
See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/jinja2/PYSEC-2019-217.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2019-217
Aliases
CVE-2019-10906
GHSA-462w-v97r-4m45
Published
2019-04-07T00:29:00Z
Modified
2023-11-08T04:00:58.644982Z
Summary
[none]
Details
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
References
https://palletsprojects.com/blog/jinja-2-10-1-released
https://lists.apache.org/thread.html/b2380d147b508bbcb90d2cad443c159e63e12555966ab4f320ee22da@%3Ccommits.airflow.apache.org%3E
https://lists.apache.org/thread.html/46c055e173b52d599c648a98199972dbd6a89d2b4c4647b0500f2284@%3Cdevnull.infra.apache.org%3E
https://lists.apache.org/thread.html/f0c4a03418bcfe70c539c5dbaf99c04c98da13bfa1d3266f08564316@%3Ccommits.airflow.apache.org%3E
https://lists.apache.org/thread.html/7f39f01392d320dfb48e4901db68daeece62fd60ef20955966739993@%3Ccommits.airflow.apache.org%3E
https://lists.apache.org/thread.html/57673a78c4d5c870d3f21465c7e2946b9f8285c7c57e54c2ae552f02@%3Ccommits.airflow.apache.org%3E
https://lists.apache.org/thread.html/320441dccbd9a545320f5f07306d711d4bbd31ba43dc9eebcfc602df@%3Cdevnull.infra.apache.org%3E
https://lists.apache.org/thread.html/2b52b9c8b9d6366a4f1b407a8bde6af28d9fc73fdb3b37695fd0d9ac@%3Cdevnull.infra.apache.org%3E
https://lists.apache.org/thread.html/09fc842ff444cd43d9d4c510756fec625ef8eb1175f14fd21de2605f@%3Cdevnull.infra.apache.org%3E
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QCDYIS254EJMBNWOG4S5QY6AOTOR4TZU/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DSW3QZMFVVR7YE3UT4YRQA272TYAL5AF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TS7IVZAJBWOHNRDMFJDIZVFCMRP6YIUQ/
https://access.redhat.com/errata/RHSA-2019:1152
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html
https://access.redhat.com/errata/RHSA-2019:1237
https://access.redhat.com/errata/RHSA-2019:1329
https://usn.ubuntu.com/4011-1/
https://usn.ubuntu.com/4011-2/
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html
https://github.com/advisories/GHSA-462w-v97r-4m45
Affected packages
PyPI
/
jinja2
Package
Name
jinja2
View open source insights on deps.dev
Purl
pkg:pypi/jinja2
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2.10.1
Affected versions
2.*
2.0rc1
2.0
2.1
2.1.1
2.2
2.2.1
2.3
2.3.1
2.4
2.4.1
2.5
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.6
2.7
2.7.1
2.7.2
2.7.3
2.8
2.8.1
2.9
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6
2.10
PYSEC-2019-217 - OSV