Rapid7

vulnerability

Red Hat: CVE-2024-56201: jinja2: Jinja has a sandbox breakout through malicious filenames (Multiple Advisories)

Severity
7
CVSS
(AV:L/AC:M/Au:S/C:C/I:C/A:C)
Published
Dec 23, 2024
Added
Jan 15, 2025
Modified
Jun 12, 2026

Description

A flaw was found in the Jinja2 package. A bug in the Jinja compiler allows an attacker that controls both the content and filename of a template to execute arbitrary Python code, regardless of Jinja's sandbox being used. An attacker needs to be able to control both the filename and the contents of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications that execute untrusted templates where the template author can also choose the template filename.

Solutions

redhat-upgrade-fence-agents-aliyunredhat-upgrade-fence-agents-allredhat-upgrade-fence-agents-amt-wsredhat-upgrade-fence-agents-apcredhat-upgrade-fence-agents-apc-snmpredhat-upgrade-fence-agents-awsredhat-upgrade-fence-agents-azure-armredhat-upgrade-fence-agents-bladecenterredhat-upgrade-fence-agents-brocaderedhat-upgrade-fence-agents-cisco-mdsredhat-upgrade-fence-agents-cisco-ucsredhat-upgrade-fence-agents-commonredhat-upgrade-fence-agents-computeredhat-upgrade-fence-agents-debuginforedhat-upgrade-fence-agents-debugsourceredhat-upgrade-fence-agents-drac5redhat-upgrade-fence-agents-eaton-snmpredhat-upgrade-fence-agents-emersonredhat-upgrade-fence-agents-epsredhat-upgrade-fence-agents-gceredhat-upgrade-fence-agents-heuristics-pingredhat-upgrade-fence-agents-hpbladeredhat-upgrade-fence-agents-ibm-powervsredhat-upgrade-fence-agents-ibm-vpcredhat-upgrade-fence-agents-ibmbladeredhat-upgrade-fence-agents-ifmibredhat-upgrade-fence-agents-ilo-moonshotredhat-upgrade-fence-agents-ilo-mpredhat-upgrade-fence-agents-ilo-sshredhat-upgrade-fence-agents-ilo2redhat-upgrade-fence-agents-intelmodularredhat-upgrade-fence-agents-ipduredhat-upgrade-fence-agents-ipmilanredhat-upgrade-fence-agents-kdumpredhat-upgrade-fence-agents-kdump-debuginforedhat-upgrade-fence-agents-kubevirtredhat-upgrade-fence-agents-kubevirt-debuginforedhat-upgrade-fence-agents-lparredhat-upgrade-fence-agents-mpathredhat-upgrade-fence-agents-openstackredhat-upgrade-fence-agents-redfishredhat-upgrade-fence-agents-rhevmredhat-upgrade-fence-agents-rsaredhat-upgrade-fence-agents-rsbredhat-upgrade-fence-agents-sbdredhat-upgrade-fence-agents-scsiredhat-upgrade-fence-agents-virshredhat-upgrade-fence-agents-vmware-restredhat-upgrade-fence-agents-vmware-soapredhat-upgrade-fence-agents-wtiredhat-upgrade-fence-agents-zvmredhat-upgrade-fence-virtredhat-upgrade-fence-virt-debuginforedhat-upgrade-fence-virtdredhat-upgrade-fence-virtd-cpgredhat-upgrade-fence-virtd-cpg-debuginforedhat-upgrade-fence-virtd-debuginforedhat-upgrade-fence-virtd-libvirtredhat-upgrade-fence-virtd-libvirt-debuginforedhat-upgrade-fence-virtd-multicastredhat-upgrade-fence-virtd-multicast-debuginforedhat-upgrade-fence-virtd-serialredhat-upgrade-fence-virtd-serial-debuginforedhat-upgrade-fence-virtd-tcpredhat-upgrade-fence-virtd-tcp-debuginforedhat-upgrade-ha-cloud-supportredhat-upgrade-ha-cloud-support-debuginfo
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.