In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
https://palletsprojects.com/blog/jinja-281-released/ | vendor advisory |
https://github.com/pallets/jinja/commit/9b53045c34e61013dc8f09b7e52a555fa16bed16 | third party advisory patch |
https://access.redhat.com/errata/RHSA-2019:1022 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:1237 | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:1260 | vendor advisory |
https://usn.ubuntu.com/4011-1/ | vendor advisory |
https://usn.ubuntu.com/4011-2/ | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:3964 | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:4062 | vendor advisory |