CVE-2024-34064
published 2024-05-06CVE-2024-34064: Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML…
PriorityP425medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.98%
58.2th percentile
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe. This vulnerability is fixed in 3.1.4.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jinja2 | < jinja2 3.1.2-1+deb12u1 (bookworm) | jinja2 3.1.2-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_nodejs_20.14.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_nodejs_20.14.0-8_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-jinja2_3.1.2-2_on_azure_linux_3.0 | — | — |
| msrc | azl3_python-jinja2_3.1.2-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_nodejs18_18.20.3-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_nodejs18_18.20.3-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python-jinja2_3.0.3-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python-jinja2_3.0.3-7_on_cbl_mariner_2.0 | — | — |
| palletsprojects | jinja | < 3.1.4 | 3.1.4 |
| pocoo | jinja2 | >= 0 < 2.11.3-1+deb11u1 | 2.11.3-1+deb11u1 |
| pocoo | jinja2 | >= 0 < 3.1.2-1+deb12u1 | 3.1.2-1+deb12u1 |
| pocoo | jinja2 | >= 0 < 3.1.3-1.1 | 3.1.3-1.1 |
| pocoo | jinja2 | >= 0 < 3.1.3-1.1 | 3.1.3-1.1 |
| pocoo | jinja2 | >= 0 < 3.1.4 | 3.1.4 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian5.4MEDIUM
vendor_msrc5.4MEDIUM
vendor_oracle5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Jinja) — CVE-2024-34064
vendor_oracle·2025-07-15·CVSS 5.4
CVE-2024-34064 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (Jinja) — CVE-2024-34064
Oracle Oracle Communications Risk Matrix: Platform (Jinja) vulnerability
CVE: CVE-2024-34064
CVSS: 5.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Jinja) — CVE-2024-34064
vendor_oracle·2025-04-15·CVSS 5.4
CVE-2024-34064 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Jinja) — CVE-2024-34064
Oracle Oracle Communications Applications Risk Matrix: Core (Jinja) vulnerability
CVE: CVE-2024-34064
CVSS: 5.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Install (Jinja) — CVE-2024-34064
vendor_oracle·2025-01-15·CVSS 5.4
CVE-2024-34064 [MEDIUM] Oracle Oracle Communications Risk Matrix: Install (Jinja) — CVE-2024-34064
Oracle Oracle Communications Risk Matrix: Install (Jinja) vulnerability
CVE: CVE-2024-34064
CVSS: 5.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Oracle
Oracle Oracle Communications Risk Matrix: Install (Jinja2) — CVE-2024-34064
vendor_oracle·2024-07-15·CVSS 5.4
CVE-2024-34064 [MEDIUM] Oracle Oracle Communications Risk Matrix: Install (Jinja2) — CVE-2024-34064
Oracle Oracle Communications Risk Matrix: Install (Jinja2) vulnerability
CVE: CVE-2024-34064
CVSS: 5.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Ubuntu
Jinja2 vulnerability
vendor_ubuntu·2024-05-28
CVE-2024-34064 Jinja2 vulnerability
Title: Jinja2 vulnerability
Summary: Jinja2 could allow cross-site scripting (XSS) attacks.
It was discovered that Jinja2 incorrectly handled certain HTML attributes
that were accepted by the xmlattr filter. An attacker could use this issue
to inject arbitrary HTML attribute keys and values to potentially execute
a cross-site scripting (XSS) attack.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
vendor_msrc·2024-05-14·CVSS 5.4
CVE-2024-34064 [MEDIUM] CWE-79 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: C
Red Hat
jinja2: accepts keys containing non-attribute characters
vendor_redhat·2024-05-06·CVSS 5.4
CVE-2024-34064 [MEDIUM] CWE-79 jinja2: accepts keys containing non-attribute characters
jinja2: accepts keys containing non-attribute characters
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insec
Debian
CVE-2024-34064: jinja2 - Jinja is an extensible templating engine. The `xmlattr` filter in affected versi...
vendor_debian·2024·CVSS 5.4
CVE-2024-34064 [MEDIUM] CVE-2024-34064: jinja2 - Jinja is an extensible templating engine. The `xmlattr` filter in affected versi...
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as us
GHSA
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
ghsa·2024-05-06·CVSS 6.1
CVE-2024-34064 [MEDIUM] CWE-79 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for the previous GHSA-h5c8-rqwp-cp95 CVE-2024-22195 only addressed spaces but not other characters.
Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the in
OSV
CVE-2024-34064: Jinja is an extensible templating engine
osv·2024-05-06·CVSS 6.1
CVE-2024-34064 [MEDIUM] CVE-2024-34064: Jinja is an extensible templating engine
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as us
OSV
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
osv·2024-05-06·CVSS 6.1
CVE-2024-34064 [MEDIUM] Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for the previous GHSA-h5c8-rqwp-cp95 CVE-2024-22195 only addressed spaces but not other characters.
Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the in
No detection rules found.
No public exploits indexed.
https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cbhttps://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfjhttps://lists.fedoraproject.org/archives/list/[email protected]/message/567XIGSZMABG6TSMYWD7MIYNJSUQQRUC/https://lists.fedoraproject.org/archives/list/[email protected]/message/GCLF44KY43BSVMTE6S53B4V5WP3FRRSE/https://lists.fedoraproject.org/archives/list/[email protected]/message/SSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS/https://github.com/pallets/jinja/commit/0668239dc6b44ef38e7a6c9f91f312fd4ca581cbhttps://github.com/pallets/jinja/security/advisories/GHSA-h75v-3vvj-5mfjhttps://lists.debian.org/debian-lts-announce/2024/12/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/567XIGSZMABG6TSMYWD7MIYNJSUQQRUC/https://lists.fedoraproject.org/archives/list/[email protected]/message/GCLF44KY43BSVMTE6S53B4V5WP3FRRSE/https://lists.fedoraproject.org/archives/list/[email protected]/message/SSCBHIL6BYKR5NRCBXP4XMP2CEEKGFVS/https://lists.fedoraproject.org/archives/list/[email protected]/message/ZALNWE3TXPPHVPSI3AZ5CTMSTAVN5UMS/
2024-05-06
Published