Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 39 Release: FEDORA-2024-f69989e7dd Critical Python Template Bug

fedora
Calendar Grey January 30, 2024
Dist Fedora Esm H88
The privilege escalation security vulnerability in python-templated-dictionary has been fixed with the Fedora update FEDORA-2024-f69989e7dd, enhancing safety
Fixing CVE-2023-6395

Summary

Dictionary where __getitem__() is run through Jinja2 template.

Update Information:

Fixing CVE-2023-6395

Change Log

* Tue Jan 16 2024 Pavel Raiskup - make the TemplatedDictionary objects picklable - use a sandboxed jinja2 environment, fixes CVE-2023-6395 * Tue Jan 16 2024 Pavel Raiskup - make the TemplatedDictionary objects picklable - Use a sandboxed jinja2 environment, CVE-2023-6395

References


[ 1 ] Bug #2258607 - CVE-2023-6395 mock: Privilege escalation for users that can access mock configuration [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2258607

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f69989e7dd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-templated-dictionary
Product: Fedora 39
Version: 1.4
Release: 1.fc39
Summary: Dictionary with Jinja2 expansion

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here