pysec-2024-26
MEDIUM CVSS 5.4 pysec
Description
Jinja2 prior to 3.1.4 accepts keys containing non-attribute characters in xmlattr filter allowing injection of arbitrary HTML attributes.
Timeline
- Published
- 2024-05-06 14:00 UTC
- Last Modified
- 2024-05-10
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 5.4 | MEDIUM | |
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 5.4,
"datePublished": "2024-05-06T14:00:00Z",
"dateUpdated": "2024-05-10T18:00:00Z",
"description": "Jinja2 prior to 3.1.4 accepts keys containing non-attribute characters in xmlattr filter allowing injection of arbitrary HTML attributes.",
"id": "PYSEC-2024-26",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"version": "3.1"
}
}
]
},
"severity": "MEDIUM",
"source": "pysec",
"title": "PySec: Jinja2 HTML attribute injection"
}