CVE-2019-10906

Related Vulnerabilities: CVE-2019-10906  

Impact: Moderate Public Date: 2019-04-06 CWE: CWE-672 Bugzilla: 1698839: CVE-2019-10906 python-jinja2: str.format_map allows sandbox escape In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

The MITRE CVE dictionary describes this issue as:

In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.

Find out more about CVE-2019-10906 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 7.7
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector Local
Attack Complexity High
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Virtualization 4 python-jinja2 Under investigation
Red Hat Satellite 6 python-jinja2 Under investigation
Red Hat OpenStack Platform 14.0 (Rocky) python-jinja2 Not affected
Red Hat OpenStack Platform 13.0 (Queens) python-jinja2 Not affected
Red Hat Gluster Storage 3 python-jinja2 Under investigation
Red Hat Enterprise Linux 7 python-jinja2 Under investigation
Red Hat Enterprise Linux 6 python-jinja2 Under investigation
Red Hat Ceph Storage 3 python-jinja2 Under investigation
Red Hat Ceph Storage 2 python-jinja2 Under investigation