Back

HIGH

python-jinja2: Sandbox escape due to information disclosure via str.format

Published Apr 8, 2019

Description

In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

Affected products

Remediation

Red Hat statement

* Red Hat OpenStack Platform is not affected by this flaw. All supported versions ship python-jinja2 packages which have already been fixed. * Red Hat Satellite 6 will receive fixes through the underlying Red Hat Enterprise Linux, so it will not issue updates to its own affected package. * Red Hat Update Infrastructure is not affected because its packaged versions of python-jinja2 do not use the Sandbox feature, nor does it allow untrusted jinja2 templates. * Red Hat Virtualization Management Appliance includes python-jinja2 as a dependency of ovirt-engine-backend, which only uses it with controlled format strings that are not exploitable. * Red Hat Ceph Storage 2 and 3 are affected by this flaw as it contains the vulnerable code and will get security fixes for python-jinja2 from Red Hat Enterprise Linux 7 channel.

Red Hat mitigation

If you don't want or you cannot upgrade Jinja2, you can override the `is_safe_attribute` method on the sandbox and explicitly disallow all `format` attributes on strings.

Metrics

Weaknesses (2)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 8, 2019
Updated Aug 6, 2024
Reserved Apr 8, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 29, 2016
GHSA-HJ2J-77XM-MC5V