Back

CRITICAL

python-jinja2: command injection in function from_string

Published Feb 15, 2019

Description

An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing

Affected products

Remediation

Red Hat statement

Red Hat Product Security does not believe this CVE assignment is valid. To the best of our knowledge, Jinja2 does not make any guarantees about being able to safely handle untrusted data by default without sandboxing modes enabled.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 15, 2019
Updated Aug 4, 2024
Reserved Feb 15, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 14, 2019