Back

HIGH

python-jinja2: str.format_map allows sandbox escape

Published Apr 6, 2019

Description

In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

Affected products

Remediation

Red Hat statement

Red Hat Virtualization Management Appliance includes python-jinja2 as a dependency of ovirt-engine-backend, which only uses it with controlled format strings that are not exploitable. Red Hat Satellite 6 will receive fixes through the underlying Red Hat Enterprise Linux, so it won't issue updates to its own affected package. This issue does not affect versions of python-jinja2 as shipped with: * Red Hat Enterprise Linux 6, and 7 as python2 does not support str.format_map. * Red Hat Update Infrastructure as it does not use the Sandbox feature, nor does it allow untrusted jinja2 templates. * Red Hat Ceph Storage 2, 3 and Red Hat Gluster Storage 3 as python2 does not support str.format_map. * Red Hat OpenStack Platform 13 or 14 as python2 does not support str.format_map.

Red Hat mitigation

If you cannot upgrade python-Jinja2, you can override the `is_safe_attribute` method on the sandbox and explicitly disallow the `format_map` method on string objects.

Metrics

Weaknesses (2)

References (36)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 6, 2019
Updated Aug 4, 2024
Reserved Apr 6, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 6, 2019
GHSA-462W-V97R-4M45