Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2024-22195
Description:Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2024.2147   1.3.6.1.4.1.25623.1.1.2.2024.1749   1.3.6.1.4.1.25623.1.1.2.2024.1971   1.3.6.1.4.1.25623.1.1.2.2024.1634   1.3.6.1.4.1.25623.1.1.2.2024.1554   1.3.6.1.4.1.25623.1.1.2.2024.2602   1.3.6.1.4.1.25623.1.1.2.2024.1535   1.3.6.1.4.1.25623.1.1.2.2024.1615   1.3.6.1.4.1.25623.1.1.2.2024.1919   1.3.6.1.4.1.25623.1.1.2.2024.2127   1.3.6.1.4.1.25623.1.1.2.2024.2092   1.3.6.1.4.1.25623.1.1.2.2024.2348   1.3.6.1.4.1.25623.1.1.2.2024.2612   1.3.6.1.4.1.25623.1.0.885627   1.3.6.1.4.1.25623.1.1.2.2024.1772   1.3.6.1.4.1.25623.1.0.885595   1.3.6.1.4.1.25623.1.1.2.2024.1944   1.3.6.1.4.1.25623.1.1.2.2024.1895   1.3.6.1.4.1.25623.1.1.2.2024.2356   1.3.6.1.4.1.25623.1.0.885611   1.3.6.1.4.1.25623.1.1.2.2024.1245   1.3.6.1.4.1.25623.1.1.1.2.2024.3715   1.3.6.1.4.1.25623.1.1.2.2024.2676   1.3.6.1.4.1.25623.1.1.2.2024.1324   1.3.6.1.4.1.25623.1.1.2.2024.2109   1.3.6.1.4.1.25623.1.1.2.2024.1346   1.3.6.1.4.1.25623.1.1.2.2024.2642   1.3.6.1.4.1.25623.1.1.2.2024.2060   1.3.6.1.4.1.25623.1.1.2.2024.1223   1.3.6.1.4.1.25623.1.1.2.2024.2065  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2024-22195
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O7YWRBX6JQCWC2XXCTZ55C7DPMGICCN3/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DELCVUUYX75I5K4Q5WMJG4MUZJA6VAIP/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5XCWZD464AJJJUBOO7CMPXQ4ROBC6JX2/
https://github.com/pallets/jinja/releases/tag/3.1.3
https://github.com/pallets/jinja/releases/tag/3.1.3
https://github.com/pallets/jinja/security/advisories/GHSA-h5c8-rqwp-cp95
https://github.com/pallets/jinja/security/advisories/GHSA-h5c8-rqwp-cp95
https://lists.debian.org/debian-lts-announce/2024/01/msg00010.html




© 1998-2025 E-Soft Inc. All rights reserved.