CVE-2024-34064

Description

Jinja is an extensible templating engine. The xmlattr filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, /, >, or =, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. The fix for CVE-2024-22195 only addressed spaces but not other characters. Accepting keys as user input is now explicitly considered an unintended use case of the xmlattr filter, and code that does so without otherwise validating the input should be flagged as insecure, regardless of Jinja version. Accepting _values_ as user input continues to be safe. This vulnerability is fixed in 3.1.4.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
1.057

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2024-34064 are fixed in Python-jinja2 3.1.4Windows
small but fast and easy to use stand-alone template engine (USN-6787-1) python-jinja2_2.10.1-2ubuntu0.3_all.debLinux
small but fast and easy to use stand-alone template engine (USN-6787-1) python3-jinja2_2.10.1-2ubuntu0.3_all.debLinux
small but fast and easy to use stand-alone template engine (USN-6787-1) python3-jinja2_3.0.3-1ubuntu0.2_all.debLinux
small but fast and easy to use stand-alone template engine (USN-6787-1) python3-jinja2_3.1.2-1ubuntu0.23.10.2_all.debLinux
small but fast and easy to use stand-alone template engine (USN-6787-1) python3-jinja2_3.1.2-1ubuntu1.1_all.debLinux
(RHSA-2024:3820)Moderate: security update fence-agents-common-4.10.0-62.el9_4.3.noarch.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-agents-compute-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-agents-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-agents-debugsource-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-agents-ibm-powervs-4.10.0-62.el9_4.3.noarch.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-agents-ibm-vpc-4.10.0-62.el9_4.3.noarch.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-agents-kdump-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-agents-kubevirt-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-agents-kubevirt-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-agents-virsh-4.10.0-62.el9_4.3.noarch.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virt-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virt-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-cpg-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-cpg-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-libvirt-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-libvirt-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-multicast-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-multicast-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-serial-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-serial-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-tcp-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update fence-virtd-tcp-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
(RHSA-2024:3820)Moderate: security update ha-cloud-support-debuginfo-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-virtd-tcp update (ELSA-2024-3820) fence-virtd-tcp-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-virtd-serial update (ELSA-2024-3820) fence-virtd-serial-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-virtd-multicast update (ELSA-2024-3820) fence-virtd-multicast-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-virtd-libvirt update (ELSA-2024-3820) fence-virtd-libvirt-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-virtd-cpg update (ELSA-2024-3820) fence-virtd-cpg-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-virtd update (ELSA-2024-3820) fence-virtd-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-virt update (ELSA-2024-3820) fence-virt-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-agents-wti update (ELSA-2024-3820) fence-agents-wti-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-vmware-soap update (ELSA-2024-3820) fence-agents-vmware-soap-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-vmware-rest update (ELSA-2024-3820) fence-agents-vmware-rest-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-virsh update (ELSA-2024-3820) fence-agents-virsh-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-scsi update (ELSA-2024-3820) fence-agents-scsi-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-sbd update (ELSA-2024-3820) fence-agents-sbd-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-rsb update (ELSA-2024-3820) fence-agents-rsb-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-rsa update (ELSA-2024-3820) fence-agents-rsa-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-rhevm update (ELSA-2024-3820) fence-agents-rhevm-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-redfish update (ELSA-2024-3820) fence-agents-redfish-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-agents-mpath update (ELSA-2024-3820) fence-agents-mpath-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-lpar update (ELSA-2024-3820) fence-agents-lpar-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-kubevirt update (ELSA-2024-3820) fence-agents-kubevirt-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-agents-kdump update (ELSA-2024-3820) fence-agents-kdump-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-agents-ipmilan update (ELSA-2024-3820) fence-agents-ipmilan-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-ipdu update (ELSA-2024-3820) fence-agents-ipdu-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-intelmodular update (ELSA-2024-3820) fence-agents-intelmodular-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-ilo2 update (ELSA-2024-3820) fence-agents-ilo2-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-ilo-ssh update (ELSA-2024-3820) fence-agents-ilo-ssh-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-ilo-mp update (ELSA-2024-3820) fence-agents-ilo-mp-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-ilo-moonshot update (ELSA-2024-3820) fence-agents-ilo-moonshot-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-ifmib update (ELSA-2024-3820) fence-agents-ifmib-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-ibmblade update (ELSA-2024-3820) fence-agents-ibmblade-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-ibm-vpc update (ELSA-2024-3820) fence-agents-ibm-vpc-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-ibm-powervs update (ELSA-2024-3820) fence-agents-ibm-powervs-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-hpblade update (ELSA-2024-3820) fence-agents-hpblade-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-heuristics-ping update (ELSA-2024-3820) fence-agents-heuristics-ping-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-eps update (ELSA-2024-3820) fence-agents-eps-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-emerson update (ELSA-2024-3820) fence-agents-emerson-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-eaton-snmp update (ELSA-2024-3820) fence-agents-eaton-snmp-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-drac5 update (ELSA-2024-3820) fence-agents-drac5-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-compute update (ELSA-2024-3820) fence-agents-compute-4.10.0-62.el9_4.3.x86_64.rpmLinux
Fence-agents-common update (ELSA-2024-3820) fence-agents-common-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-cisco-ucs update (ELSA-2024-3820) fence-agents-cisco-ucs-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-cisco-mds update (ELSA-2024-3820) fence-agents-cisco-mds-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-brocade update (ELSA-2024-3820) fence-agents-brocade-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-bladecenter update (ELSA-2024-3820) fence-agents-bladecenter-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-apc-snmp update (ELSA-2024-3820) fence-agents-apc-snmp-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-apc update (ELSA-2024-3820) fence-agents-apc-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-amt-ws update (ELSA-2024-3820) fence-agents-amt-ws-4.10.0-62.el9_4.3.noarch.rpmLinux
Fence-agents-all update (ELSA-2024-3820) fence-agents-all-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-virtd-tcp-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-virtd-serial-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-virtd-multicast-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-virtd-libvirt-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-virtd-cpg-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-virtd-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-virt-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-agents-virsh-4.10.0-62.el9_4.3.noarch.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-agents-kubevirt-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-agents-ibm-vpc-4.10.0-62.el9_4.3.noarch.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-agents-ibm-powervs-4.10.0-62.el9_4.3.noarch.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-agents-compute-4.10.0-62.el9_4.3.x86_64.rpmLinux
fence-agents security update (RLSA-2024:3820) fence-agents-common-4.10.0-62.el9_4.3.noarch.rpmLinux
(RHSA-2024:4231)Moderate: security update python3-jinja2-2.10.1-5.el8_10.noarch.rpmLinux
ansible-core Security Update (ALAS-2024-644) ansible-test-2.15.3-1.amzn2023.0.4.x86_64.rpmLinux
ansible-core Security Update (ALAS-2024-644) ansible-core-2.15.3-1.amzn2023.0.4.x86_64.rpmLinux
python-jinja2 Security Update (ALAS-2024-2574) python-jinja2-2.7.2-3.amzn2.0.2.noarch.rpmLinux
python-jinja2 Security Update (ALAS-2024-645) python3-jinja2-2.11.3-1.amzn2023.0.4.noarch.rpmLinux
Python3-jinja2 update (ELSA-2024-4231) python3-jinja2-2.10.1-5.el8_10.noarch.rpmLinux
python-jinja2 security update (RLSA-2024:4231) python3-jinja2-2.10.1-5.el8_10.noarch.rpmLinux
SUSE-SU-2024:1863-1(Basesystem Module 15-SP6 ) python3-Jinja2-2.10.1-150000.3.13.1.noarch.rpmLinux
SUSE-SU-2024:1863-1(Basesystem Module 15-SP5 ) python3-Jinja2-2.10.1-150000.3.13.1.noarch.rpmLinux
Fence-agents-kdump update (ELSA-2024-6309) fence-agents-kdump-4.2.1-129.el8_10.4.x86_64.rpmLinux
Fence-agents-ipmilan update (ELSA-2024-6309) fence-agents-ipmilan-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-ipdu update (ELSA-2024-6309) fence-agents-ipdu-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-intelmodular update (ELSA-2024-6309) fence-agents-intelmodular-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-ilo2 update (ELSA-2024-6309) fence-agents-ilo2-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-ilo-ssh update (ELSA-2024-6309) fence-agents-ilo-ssh-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-ilo-mp update (ELSA-2024-6309) fence-agents-ilo-mp-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-ilo-moonshot update (ELSA-2024-6309) fence-agents-ilo-moonshot-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-ifmib update (ELSA-2024-6309) fence-agents-ifmib-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-ibmblade update (ELSA-2024-6309) fence-agents-ibmblade-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-ibm-vpc update (ELSA-2024-6309) fence-agents-ibm-vpc-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-ibm-powervs update (ELSA-2024-6309) fence-agents-ibm-powervs-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-hpblade update (ELSA-2024-6309) fence-agents-hpblade-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-all update (ELSA-2024-6309) fence-agents-all-4.2.1-129.el8_10.4.x86_64.rpmLinux
Fence-agents-eps update (ELSA-2024-6309) fence-agents-eps-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-emerson update (ELSA-2024-6309) fence-agents-emerson-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-eaton-snmp update (ELSA-2024-6309) fence-agents-eaton-snmp-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-drac5 update (ELSA-2024-6309) fence-agents-drac5-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-compute update (ELSA-2024-6309) fence-agents-compute-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-common update (ELSA-2024-6309) fence-agents-common-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-cisco-ucs update (ELSA-2024-6309) fence-agents-cisco-ucs-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-cisco-mds update (ELSA-2024-6309) fence-agents-cisco-mds-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-brocade update (ELSA-2024-6309) fence-agents-brocade-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-bladecenter update (ELSA-2024-6309) fence-agents-bladecenter-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-apc-snmp update (ELSA-2024-6309) fence-agents-apc-snmp-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-apc update (ELSA-2024-6309) fence-agents-apc-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-amt-ws update (ELSA-2024-6309) fence-agents-amt-ws-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-heuristics-ping update (ELSA-2024-6309) fence-agents-heuristics-ping-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-kubevirt update (ELSA-2024-6309) fence-agents-kubevirt-4.2.1-129.el8_10.4.x86_64.rpmLinux
Fence-agents-wti update (ELSA-2024-6309) fence-agents-wti-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-vmware-soap update (ELSA-2024-6309) fence-agents-vmware-soap-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-vmware-rest update (ELSA-2024-6309) fence-agents-vmware-rest-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-virsh update (ELSA-2024-6309) fence-agents-virsh-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-scsi update (ELSA-2024-6309) fence-agents-scsi-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-sbd update (ELSA-2024-6309) fence-agents-sbd-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-rsb update (ELSA-2024-6309) fence-agents-rsb-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-rsa update (ELSA-2024-6309) fence-agents-rsa-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-rhevm update (ELSA-2024-6309) fence-agents-rhevm-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-redfish update (ELSA-2024-6309) fence-agents-redfish-4.2.1-129.el8_10.4.x86_64.rpmLinux
Fence-agents-mpath update (ELSA-2024-6309) fence-agents-mpath-4.2.1-129.el8_10.4.noarch.rpmLinux
Fence-agents-lpar update (ELSA-2024-6309) fence-agents-lpar-4.2.1-129.el8_10.4.noarch.rpmLinux
(RHSA-2024:9150)Moderate: security update python3-jinja2-2.11.3-6.el9.noarch.rpmLinux
Python3-jinja2 update (ELSA-2024-9150) python3-jinja2-2.11.3-6.el9.noarch.rpmLinux
python3 update (TU-CESAS-0005) python3-jinja2-2.11.3-7.el9.noarch.rpmLinux
kernel update (TU-CESAS-0005) kernel-headers-5.14.0-554.el9.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-devel-matched-5.14.0-554.el9.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-devel-5.14.0-554.el9.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-debug-devel-matched-5.14.0-554.el9.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-headers-6.12.0-72.el10.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-headers-5.14.0-578.el9.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-devel-matched-6.12.0-72.el10.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-devel-matched-5.14.0-578.el9.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-devel-6.12.0-72.el10.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-devel-5.14.0-578.el9.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-debug-devel-matched-6.12.0-72.el10.x86_64.rpmLinux
kernel update (TU-CESAS-0005) kernel-debug-devel-matched-5.14.0-578.el9.x86_64.rpmLinux
python3 update (TU-CESAS-0005) python3-jinja2-2.11.3-8.el9.noarch.rpmLinux
Vulnerabilities CVE-2024-34064 are fixed in Python-jinja2 for linux 3.1.4Linux
Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability (CVE-2024-34064)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234