VDB
BDU%3A2025-00945
BDU%3A2025-00945
PUBLISHED
CVSS 6.400000095367432 MEDIUM
Уязвимость инструмента для html-шаблонизации jinja, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовый скриптинг (XSS)
Risk Scores
CVSS 2.0
6.400000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», АО «НТЦ ИТ РОСА» | SUSE Linux Enterprise Server for SAP Applications, OpenSUSE Leap, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, Red Hat Enterprise Linux, SUSE Linux Enterprise Module for Public Cloud, openSUSE Tumbleweed, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Micro, openSUSE Leap Micro, Suse Linux Enterprise Desktop, SUSE Linux Enterprise Module for Basesystem, АЛЬТ СП 10, SUSE Liberty Linux, Red Hat Ansible Automation Platform, jinja, SUSE Linux Enterprise Module for Advanced Systems Management, SUSE Manager Client Tools, SUSE Linux Enterprise Module for Python 3, ROSA Virtualization 3.0 (запись в едином реестре российских программ №21308) |
Timeline
- Feb 3, 2025 CVE Published
- Oct 29, 2025 CVE Updated
References
- https://redos.red-soft.ru/support/secure/ url
- https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cb url
- https://security-tracker.debian.org/tracker/CVE-2024-34064 url
- https://access.redhat.com/security/cve/cve-2024-34064 url
- https://www.suse.com/security/cve/CVE-2024-34064.html url
- https://wiki.astralinux.ru/astra-linux-se18-bulletin-2025-0114SE18MD url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2769 url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory