Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The fix for CVE-2025-27516 announced in DLA-4126 does not supporting Python 2. Now, the support of Python 2 was re-instated. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4126-2
USN-7343-1 introduced a regression in Jinja2.. ========================================================================== Ubuntu Security Notice USN-7343-2 March 12, 2025 jinja2 regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: USN-7343-1 introduced a regression in Jinja2. Software Description: - jinja2: small but fast and easy to use stand-alone template engine Details: USN-7343-1 fixed vulnerabilities in Jinja2. The update introduced a regression when attempting to import Jinja2 on Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Rafal Krupinski discovered that Jinja2 did not properly restrict the execution of code in situations where templates are used maliciously. An attacker with control over a template's filename and content could potentially use this issue to enable the execution of arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2024-56201) It was discovered that Jinja2 sandboxed environments could be escaped through a call to a string format method. An attacker could possibly use this issue to enable the execution of arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2024-56326) It was discovered that Jinja2 sandboxed environments could be escaped through the malicious use of certain filters. An attacker could possibly use this issue to enable the execution of arbitrary code. (CVE-2025-27516) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS python-jinja2 2.10.1-2ubuntu0.6 python3-jinja2 2.10.1-2ubuntu0.6 Ubuntu 18.04 LTS python-jinja2 2.10-1ubuntu0.18.04.1+esm5 Available with Ubuntu Pro python3-jinja2 2.10-1ubuntu0.18.04.1+esm5 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7343-2 https://ubuntu.com/security/notices/USN-7343-1 https://bugs.launchpad.net/ubuntu/+source/jinja2/+bug/2102129 Package Information: https://launchpad.net/ubuntu/+source/jinja2/2.10.1-2ubuntu0.6 . Jinja2 update for Ubuntu addresses a critical regression issue from a previous advisory impacting template execution. . usn-7343-1, introduced, regression, jinja2, ======================================================. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Jinja2.. ========================================================================== Ubuntu Security Notice USN-7343-1 March 11, 2025 jinja2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Jinja2. Software Description: - jinja2: small but fast and easy to use stand-alone template engine Details: Rafal Krupinski discovered that Jinja2 did not properly restrict the execution of code in situations where templates are used maliciously. An attacker with control over a template's filename and content could potentially use this issue to enable the execution of arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2024-56201) It was discovered that Jinja2 sandboxed environments could be escaped through a call to a string format method. An attacker could possibly use this issue to enable the execution of arbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2024-56326) It was discovered that Jinja2 sandboxed environments could be escaped through the malicious use of certain filters. An attacker could possibly use this issue to enable the execution of arbitrary code. (CVE-2025-27516) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 python3-jinja2 3.1.3-1ubuntu1.24.10.2 Ubuntu 24.04 LTS python3-jinja2 3.1.2-1ubuntu1.3 Ubuntu 22.04 LTS python3-jinja2 3.0.3-1ubuntu0.4 Ubuntu 20.04 LTS python-jinja2 2.10.1-2ubuntu0.5 python3-jinja2 2.10.1-2ubuntu0.5 Ubuntu 18.04 LTS python-jinja2 2.10-1ubuntu0.18.04.1+esm4 Available with Ubuntu Pro python3-jinja2 2.10-1ubuntu0.18.04.1+esm4 Available with Ubuntu Pro Ubuntu 16.04 LTS python-jinja2 2.8-1ubuntu0.1+esm5 Available with Ubuntu Pro python3-jinja2 2.8-1ubuntu0.1+esm5 Available with Ubuntu Pro Ubuntu 14.04 LTS python-jinja2 2.7.2-2ubuntu0.1~esm6 Available with Ubuntu Pro python3-jinja2 2.7.2-2ubuntu0.1~esm6 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7343-1 CVE-2024-56201, CVE-2024-56326, CVE-2025-27516 Package Information: https://launchpad.net/ubuntu/+source/jinja2/3.1.3-1ubuntu1.24.10.2 https://launchpad.net/ubuntu/+source/jinja2/3.1.2-1ubuntu1.3 https://launchpad.net/ubuntu/+source/jinja2/3.0.3-1ubuntu0.4 https://launchpad.net/ubuntu/+source/jinja2/2.10.1-2ubuntu0.5 . Security issues fixed in Jinja2 for multiple Ubuntu versions, addressing execution risks and code exploitation.. security, jinja2, ======================================================. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in jinja2.. ========================================================================== Ubuntu Security Notice USN-7244-1 January 30, 2025 jinja2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in jinja2. Software Description: - jinja2: small but fast and easy to use stand-alone template engine Details: It was discovered that Jinja2 incorrectly handled certain filenames when compiling template content. An attacker could possibly use this issue to execute arbitrary code. (CVE-2024-56201) It was discovered that Jinja2 incorrectly handled string formatting calls. An attacker could possibly use this issue to execute arbitrary code. (CVE-2024-56326) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 python3-jinja2 3.1.3-1ubuntu1.24.10.1 Ubuntu 24.04 LTS python3-jinja2 3.1.2-1ubuntu1.2 Ubuntu 22.04 LTS python3-jinja2 3.0.3-1ubuntu0.3 Ubuntu 20.04 LTS python-jinja2 2.10.1-2ubuntu0.4 python3-jinja2 2.10.1-2ubuntu0.4 Ubuntu 18.04 LTS python-jinja2 2.10-1ubuntu0.18.04.1+esm3 Available with Ubuntu Pro python3-jinja2 2.10-1ubuntu0.18.04.1+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7244-1 CVE-2024-56201, CVE-2024-56326 Package Information: https://launchpad.net/ubuntu/+source/jinja2/3.1.3-1ubuntu1.24.10.1 https://launchpad.net/ubuntu/+source/jinja2/3.1.2-1ubuntu1.2 https://launchpad.net/ubuntu/+source/jinja2/3.0.3-1ubuntu0.3 https://launchpad.net/ubuntu/+source/jinja2/2.10.1-2ubuntu0.4 . New updates for Ubuntu tackle multiple jinja2 security flaws, underscoring the importance of prompt patching.. jinja2 Updates, Ubuntu Security Advisory, code execution risks. . Severity: Critical. LinuxSecurity.com Team
This update fixes a regression that broke the python-jinja2 package for Python 2. Note that while this regression has been fixed, running applications . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3988-2
HTML attribute injection has been fixed in Jinja, a Python templating engine. For Debian 11 bullseye, these problems have been fixed in version 2.11.3-1+deb11u1. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3988-1
Jinja2 could allow cross-site scripting (XSS) attacks.. ========================================================================== Ubuntu Security Notice USN-6787-1 May 28, 2024 jinja2 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Jinja2 could allow cross-site scripting (XSS) attacks. Software Description: - jinja2: small but fast and easy to use stand-alone template engine Details: It was discovered that Jinja2 incorrectly handled certain HTML attributes that were accepted by the xmlattr filter. An attacker could use this issue to inject arbitrary HTML attribute keys and values to potentially execute a cross-site scripting (XSS) attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-jinja2 3.1.2-1ubuntu1.1 Ubuntu 23.10 python3-jinja2 3.1.2-1ubuntu0.23.10.2 Ubuntu 22.04 LTS python3-jinja2 3.0.3-1ubuntu0.2 Ubuntu 20.04 LTS python-jinja2 2.10.1-2ubuntu0.3 python3-jinja2 2.10.1-2ubuntu0.3 Ubuntu 18.04 LTS python-jinja2 2.10-1ubuntu0.18.04.1+esm2 Available with Ubuntu Pro python3-jinja2 2.10-1ubuntu0.18.04.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS python-jinja2 2.8-1ubuntu0.1+esm3 Available with Ubuntu Pro python3-jinja2 2.8-1ubuntu0.1+esm3 Available with Ubuntu Pro Ubuntu 14.04 LTS python-jinja2 2.7.2-2ubuntu0.1~esm3 Available with Ubuntu Pro python3-jinja2 2.7.2-2ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6787-1 CVE-2024-34064 Package Information: https://launchpad.net/ubuntu/+source/jinja2/3.1.2-1ubuntu1.1 https://launchpad.net/ubuntu/+source/jinja2/3.1.2-1ubuntu0.23.10.2 https://launchpad.net/ubuntu/+source/jinja2/3.0.3-1ubuntu0.2 https://launchpad.net/ubuntu/+source/jinja2/2.10.1-2ubuntu0.3 . The Jinja2 security flaw exposes cross-site scripting risks; Ubuntu has released updates providing solutions to mitigate this vulnerability.. jinja2 security,xss threat,ubuntu advisory,software patch,update instructions. . Severity: Important. LinuxSecurity.com Team
Update to jinja2-3.1.4, fixes CVE-2024-34064.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-e609c057ad 2024-05-16 01:08:08.062410 -------------------------------------------------------------------------------- Name : mingw-python-jinja2 Product : Fedora 39 Version : 3.1.4 Release : 1.fc39 URL : https://palletsprojects.com/projects/jinja/ Summary : MinGW Windows Python jinja2 library Description : MinGW Windows Python jinja2 library. -------------------------------------------------------------------------------- Update Information: Update to jinja2-3.1.4, fixes CVE-2024-34064. -------------------------------------------------------------------------------- ChangeLog: * Tue May 7 2024 Sandro Mani - 3.1.4-1 - Update to 3.1.4 * Thu Jan 25 2024 Fedora Release Engineering - 3.1.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 3.1.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2279486 - TRIAGE CVE-2024-34064 mingw-python-jinja2: jinja2: accepts keys containing non-attribute characters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2279486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-e609c057ad' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.