Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Debian 10: FEDORA-2019-e41e19457b Critical: Python-Jinja2 Sandbox Escape

fedora
Calendar Grey April 27, 2019
Dist Fedora Esm H88
Important security patch for python-jinja2 impacts the sandbox functionality, Fedora users are urged to upgrade.
Security fix for CVE-2019-10906.

Summary

Jinja2 is a template engine written in pure Python. It provides a

Django inspired non-XML syntax but supports inline expressions and an

optional sandboxed environment.

If you have any exposure to other text-based template languages, such

as Smarty or Django, you should feel right at home with Jinja2. It's

both designer and developer friendly by sticking to Python's

principles and adding functionality useful for templating

environments.

Security fix for CVE-2019-10906.

* Wed Apr 10 2019 Thomas Moschny - 2.10.1-1

- Update to 2.10.1.

- Update specfile.

[ 1 ] Bug #1698839 - CVE-2019-10906 python-jinja2: str.format_map allows sandbox escape

https://bugzilla.redhat.com/show_bug.cgi?id=1698839

su -c 'dnf upgrade --advisory FEDORA-2019-e41e19457b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 30
Version: 2.10.1
Release: 1.fc30
Summary: General purpose template engine

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here