漏洞信息详情
Pallets Jinja 格式化字符串错误漏洞
漏洞简介
Pallets Jinja是一款使用Python语言编写的模板引擎。
Pallets Jinja中存在格式化字符串错误漏洞。该漏洞源于网络系统或产品接收外部格式化字符串作为参数时,对参数类型、数量等过滤不严格。以下产品及版本受到影响:Pallets Jinja 2.8.1之前版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://palletsprojects.com/blog/jinja-281-released/
参考网址
来源:palletsprojects.com
链接:https://palletsprojects.com/blog/jinja-281-released/
来源:github.com
链接:https://github.com/pallets/jinja/commit/9b53045c34e61013dc8f09b7e52a555fa16bed16
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:1260
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:1022
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:1237
来源:UBUNTU
链接:https://usn.ubuntu.com/4011-1/
来源:UBUNTU
链接:https://usn.ubuntu.com/4011-2/
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191156-1.html
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:1022
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:3964
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:1237
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4071
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:4069
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/155536/Red-Hat-Security-Advisory-2019-4062-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/81134
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4549/
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2016-10745
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.4542/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80346
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80478
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152758/Red-Hat-Security-Advisory-2019-1022-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/155465/Red-Hat-Security-Advisory-2019-3964-01.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.4487/
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152955/Red-Hat-Security-Advisory-2019-1237-01.html
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/153000/Red-Hat-Security-Advisory-2019-1260-01.html
受影响实体
暂无
补丁
- Pallets Jinja 安全漏洞的修复措施<!--2019-4-8-->
还没有评论,来说两句吧...