security advisoryDebianvulnerability
HTML attribute injection has been fixed in Jinja, a Python templating engine. For Debian 11 bullseye, these problems have been fixed in version 2.11.3-1+deb11u1. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3988-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk December 09, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : jinja2 Version : 2.11.3-1+deb11u1 CVE ID : CVE-2024-22195 CVE-2024-34064 Debian Bug : 1060748 1070712 HTML attribute injection has been fixed in Jinja, a Python templating engine. For Debian 11 bullseye, these problems have been fixed in version 2.11.3-1+deb11u1. We recommend that you upgrade your jinja2 packages. For the detailed security status of jinja2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jinja2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest security patch for jinja2 on Debian 11 bullseye resolves vulnerabilities related to HTML attribute injection with the release of version 2.11.3-1+deb11u1.. jinja2 security update, Debian LTS advisory, HTML injection fix, Python templating engine. . Severity: Critical. LinuxSecurity.com Team
Dec 08, 2024
•Critical
Debian LTS