In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
References
Configurations
Information
Published : 2019-04-08 06:29
Updated : 2019-06-06 09:29
NVD link : CVE-2016-10745
Mitre link : CVE-2016-10745
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
palletsprojects
- jinja