cbcvebase.
CVE-2024-34064
published 2024-05-06

CVE-2024-34064: Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML…

PriorityP425medium5.4CVSS 3.1
AVNACLPRNUIRSUCLILAN
EPSS
0.98%
58.2th percentile
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the `xmlattr` filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe. This vulnerability is fixed in 3.1.4.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianjinja2< jinja2 3.1.2-1+deb12u1 (bookworm)jinja2 3.1.2-1+deb12u1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrcazl3_mozjs_102.15.1-1_on_azure_linux_3.0
msrcazl3_nodejs_20.14.0-1_on_azure_linux_3.0
msrcazl3_nodejs_20.14.0-8_on_azure_linux_3.0
msrcazl3_python-jinja2_3.1.2-2_on_azure_linux_3.0
msrcazl3_python-jinja2_3.1.2-3_on_azure_linux_3.0
msrccbl2_nodejs18_18.20.3-4_on_cbl_mariner_2.0
msrccbl2_nodejs18_18.20.3-5_on_cbl_mariner_2.0
msrccbl2_python-jinja2_3.0.3-4_on_cbl_mariner_2.0
msrccbl2_python-jinja2_3.0.3-7_on_cbl_mariner_2.0
palletsprojectsjinja< 3.1.43.1.4
pocoojinja2>= 0 < 2.11.3-1+deb11u12.11.3-1+deb11u1
pocoojinja2>= 0 < 3.1.2-1+deb12u13.1.2-1+deb12u1
pocoojinja2>= 0 < 3.1.3-1.13.1.3-1.1
pocoojinja2>= 0 < 3.1.3-1.13.1.3-1.1
pocoojinja2>= 0 < 3.1.43.1.4

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian5.4MEDIUM
vendor_msrc5.4MEDIUM
vendor_oracle5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.