Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Med] Snyk: Sandbox Escape (due 6/10/19) #2822

Closed
Tracked by #137 ...
rjayasekera opened this issue Apr 11, 2019 · 0 comments · Fixed by #2919
Closed
Tracked by #137 ...

[Med] Snyk: Sandbox Escape (due 6/10/19) #2822

rjayasekera opened this issue Apr 11, 2019 · 0 comments · Fixed by #2919
Assignees
Labels
Security: moderate Remediate within 60 days
Milestone

Comments

@rjayasekera
Copy link
Contributor

https://app.snyk.io/vuln/SNYK-PYTHON-JINJA2-174126

Overview
jinja2 is a template engine written in pure Python. It provides a Django inspired non-XML syntax but supports inline expressions and an optional sandboxed environment.

Affected versions of this package are vulnerable to Sandbox Escape via the str.format_map.

Detailed paths
Introduced through: project@0.0.0 › django-jinja@2.4.1 › jinja2@2.9.6
Introduced through: project@0.0.0 › jinja2@2.9.6

Remediation
Upgrade jinja2 to version 2.10.1 or higher.

@rjayasekera rjayasekera added this to the Sprint 8.6 milestone Apr 11, 2019
@pkfec pkfec changed the title Sandbox Escape -- MEDIUM SEVERITY (from check logs [MEDIUM] Sandbox Escape fix by 20190610 Apr 11, 2019
@pkfec pkfec modified the milestones: Sprint 8.6, Sprint 8.7 Apr 11, 2019
@jason-upchurch jason-upchurch added the Security: moderate Remediate within 60 days label May 16, 2019
@jason-upchurch jason-upchurch modified the milestones: Sprint 8.7, Sprint 9.1 May 16, 2019
@jason-upchurch jason-upchurch changed the title [MEDIUM] Sandbox Escape fix by 20190610 [Med] Snyk: Sandbox Escape (due 6/10/19) May 16, 2019
lbeaufort added a commit that referenced this issue May 31, 2019
#2822 - Update requirements.txt to Jinja2==2.10.1 from 2.9.6
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Security: moderate Remediate within 60 days
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants