All vulnerabilities

CVE-2016-10745

Jinja2 sandbox escape vulnerability

Description

In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

Patch Available

Fix available through Seal Security. 

No upgrade required, protect your application instantly.

Fix without upgrading
Score
8.6
Severity
High
Ecosystem
Python
Publish Date
April 8, 2019
Modified Date
November 7, 2023
Score Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected Versions