In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
References
Configurations
History
No history.
Information
Published : 2019-04-08 13:29
Updated : 2024-02-28 17:08
NVD link : CVE-2016-10745
Mitre link : CVE-2016-10745
CVE.ORG link : CVE-2016-10745
JSON object : View
Products Affected
palletsprojects
- jinja
CWE
CWE-134
Use of Externally-Controlled Format String