SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-8341

The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it.

CRITICAL 9.8EPSS 44.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 44.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
44.78% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-94
Affected
pocoo/jinja2 · opensuse/leap
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.