pysec-2024-26

MEDIUM CVSS 5.4 pysec
Description

Jinja2 prior to 3.1.4 accepts keys containing non-attribute characters in xmlattr filter allowing injection of arbitrary HTML attributes.

Timeline
Published
2024-05-06 14:00 UTC
Last Modified
2024-05-10
CVSS Details

CVSS details not available.

Affected Products

No product information available.

CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 5.4 MEDIUM
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 5.4,
  "datePublished": "2024-05-06T14:00:00Z",
  "dateUpdated": "2024-05-10T18:00:00Z",
  "description": "Jinja2 prior to 3.1.4 accepts keys containing non-attribute characters in xmlattr filter allowing injection of arbitrary HTML attributes.",
  "id": "PYSEC-2024-26",
  "metrics": {
    "cvssMetricV31": [
      {
        "cvssData": {
          "baseScore": 5.4,
          "baseSeverity": "MEDIUM",
          "version": "3.1"
        }
      }
    ]
  },
  "severity": "MEDIUM",
  "source": "pysec",
  "title": "PySec: Jinja2 HTML attribute injection"
}
View JSON API Download JSON