CVE-2019-8341 PUBLISHED

An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing

EPSS 36.59% · 97.1th percentile

Risk Scores

EPSS Score
36.59%
97.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSjinja20, 2.8-1, 2.8-1ubuntu0.1
Ubuntu:Pro:14.04:LTSjinja22.7.2-2ubuntu0.1~esm3, 2.7.2-2ubuntu0.1~esm4, 2.7.2-2ubuntu0.1~esm6
Ubuntu:Pro:18.04:LTSjinja20, 2.9.6-1, 2.10-1

Timeline

References

Open in Interactive Console →