CVE-2016-10745: High severity palletsprojects Jinja vulnerability
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/python-jinja2to a version that resolves this vulnerability.Fixed in 2.8.1 - Upgrade
Upgrade
pip/Jinja2to a version that resolves this vulnerability.Fixed in 2.8.1 - Upgrade
Upgrade
debian/jinja2to a version that resolves this vulnerability.Fixed in 2.11.3-1Fixed in 2.11.3-1+deb11u4Fixed in 3.1.2-1+deb12u3Fixed in 3.1.6-1Fixed in 3.1.6-3 - Upgrade
Upgrade
pallets/jinjato a version that resolves this vulnerability.Fixed in 2.8.1
Event History
Frequently Asked Questions
What is CVE-2016-10745?
CVE-2016-10745 is a vulnerability in Pallets Jinja before version 2.8.1 that allows a sandbox escape.
How severe is CVE-2016-10745?
CVE-2016-10745 has a severity rating of 8.6 out of 10.
What is affected by CVE-2016-10745?
Pallets Jinja versions before 2.8.1 are affected by CVE-2016-10745.
How can I fix CVE-2016-10745?
To fix CVE-2016-10745, update Pallets Jinja to version 2.8.1 or later.
Where can I find more information about CVE-2016-10745?
You can find more information about CVE-2016-10745 at the following references: [link1], [link2], [link3].