CVE-2016-10745

Aliases:GHSA-hj2j-77xm-mc5vPYSEC-2019-220
Modified
Published: 08 Apr 2019, 13:00
Last modified:06 Aug 2024, 03:30

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.6 HIGH
v3.0 (nvd)
EPSS Score
1.02% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Apr 2019, 13:00
Published
Vulnerability first disclosed
06 Aug 2024, 03:30
Last Modified
Vulnerability information updated

Description

In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

CVSS Metrics

  • v4.0HIGHScore: 7.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
  • v3.0HIGHScore: 8.6CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 1.02% Percentile: 78%

Techniques & Countermeasures

  • CWE-134Use of Externally-Controlled Format String

    The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Systems

  • palletsprojectsjinja

    < 2.8.1

  • PyPIjinja2

    < 9b53045c34e61013dc8f09b7e52a555fa16bed16 | < 2.8.1

References (18)