|
|
Log in / Subscribe / Register

Mageia alert MGASA-2024-0199 (python-jinja2)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2024-0199: Updated python-jinja2 packages fix security vulnerabilities
Date:  Fri, 31 May 2024 17:16:00 +0200
Message-ID:  <20240531151600.5ED43A00C5@duvel.mageia.org>
Archive-link:  Article

MGASA-2024-0199 - Updated python-jinja2 packages fix security vulnerabilities Publication date: 31 May 2024 URL: https://advisories.mageia.org/MGASA-2024-0199.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-22195, CVE-2024-34064 Description: It was discovered that Jinja2 incorrectly handled certain HTML attributes that were accepted by the xmlattr filter. An attacker could use this issue to inject arbitrary HTML attribute keys and values to potentially execute a cross-site scripting (XSS) attack. References: - https://bugs.mageia.org/show_bug.cgi?id=33253 - https://ubuntu.com/security/notices/USN-6599-1 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-2... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3... SRPMS: - 9/core/python-jinja2-3.1.4-1.mga9


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds