Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 38: 2024-4bd03c989 moderate: Fix for Jinja2 Privilege Escalation

fedora
Calendar Grey February 1, 2024
Dist Fedora Esm H88
Address CVE-2023-6395 in the python-templated-dictionary library on Fedora 38 by applying updates targeting privilege escalation issues to enhance security.
Fixing CVE-2023-6395

Summary

Dictionary where __getitem__() is run through Jinja2 template.

Update Information:

Fixing CVE-2023-6395

Change Log

* Tue Jan 16 2024 Pavel Raiskup - make the TemplatedDictionary objects picklable - use a sandboxed jinja2 environment, fixes CVE-2023-6395 * Tue Jan 16 2024 Pavel Raiskup - make the TemplatedDictionary objects picklable - Use a sandboxed jinja2 environment, CVE-2023-6395

References


[ 1 ] Bug #2258607 - CVE-2023-6395 mock: Privilege escalation for users that can access mock configuration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2258607

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-4bd03c989b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-templated-dictionary
Product: Fedora 38
Version: 1.4
Release: 1.fc38
Summary: Dictionary with Jinja2 expansion

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here