cbcvebase.
CVE-2024-56201
published 2024-12-23

CVE-2024-56201: Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the…

PriorityP349high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.31%
22.9th percentile
Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename of a template to execute arbitrary Python code, regardless of if Jinja's sandbox is used. To exploit the vulnerability, an attacker needs to control both the filename and the contents of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications which execute untrusted templates where the template author can also choose the template filename. This vulnerability is fixed in 3.1.5.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianjinja2< jinja2 3.1.2-1+deb12u2 (bookworm)jinja2 3.1.2-1+deb12u2 (bookworm)
msrcazl3_nodejs_20.14.0-8_on_azure_linux_3.0
msrcazl3_python-jinja2_3.1.2-2_on_azure_linux_3.0
msrcazl3_python-jinja2_3.1.2-3_on_azure_linux_3.0
msrccbl2_python-jinja2_3.0.3-5_on_cbl_mariner_2.0
msrccbl2_python-jinja2_3.0.3-7_on_cbl_mariner_2.0
palletsjinja
palletsprojectsjinja>= 3.0.0 < 3.1.53.1.5
pocoojinja2>= 0 < 3.1.2-1+deb12u23.1.2-1+deb12u2
pocoojinja2>= 0 < 3.1.5-13.1.5-1
pocoojinja2>= 0 < 3.1.5-13.1.5-1
pocoojinja2>= 0 < 2.10.1-2ubuntu0.52.10.1-2ubuntu0.5
pocoojinja2>= 0 < 2.10.1-2ubuntu0.42.10.1-2ubuntu0.4
pocoojinja2>= 0 < 2.10.1-2ubuntu0.62.10.1-2ubuntu0.6
pocoojinja2>= 0 < 3.0.3-1ubuntu0.43.0.3-1ubuntu0.4
pocoojinja2>= 0 < 3.0.3-1ubuntu0.33.0.3-1ubuntu0.3
pocoojinja2>= 0 < 3.1.2-1ubuntu1.33.1.2-1ubuntu1.3
pocoojinja2>= 0 < 3.1.2-1ubuntu1.23.1.2-1ubuntu1.2
pocoojinja2>= 0 < 2.7.2-2ubuntu0.1~esm62.7.2-2ubuntu0.1~esm6
pocoojinja2>= 0 < 2.8-1ubuntu0.1+esm52.8-1ubuntu0.1+esm5
pocoojinja2>= 0 < 2.10-1ubuntu0.18.04.1+esm42.10-1ubuntu0.18.04.1+esm4
pocoojinja2>= 0 < 2.10-1ubuntu0.18.04.1+esm32.10-1ubuntu0.18.04.1+esm3
pocoojinja2>= 0 < 2.10-1ubuntu0.18.04.1+esm52.10-1ubuntu0.18.04.1+esm5
pocoojinja2>= 3.0.0 < 3.1.53.1.5

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv4.05.4MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.4MEDIUM
vendor_msrc8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.