{"schema_version":"1.7.5","id":"CVE-2019-8341","published":"2019-02-15T07:29:00.257Z","modified":"2026-07-08T05:55:10.104832567Z","related":["SUSE-FU-2022:0444-1","SUSE-FU-2022:0445-1","SUSE-SU-2019:1156-1","SUSE-SU-2019:1554-1","SUSE-SU-2020:3096-1","SUSE-SU-2020:3897-1","openSUSE-SU-2019:1395-1"],"details":"An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the \"source\" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pallets/jinja","events":[{"introduced":"7c3b7ca95cb17589dd64fddc957035336180b90d"},{"last_affected":"7c3b7ca95cb17589dd64fddc957035336180b90d"}],"database_specific":{"cpe":"cpe:2.3:a:pocoo:jinja2:2.10:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.10"},{"last_affected":"2.10"}],"source":"CPE_STRING"}}],"versions":["2.10","2.10.x"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-8341.json"}}],"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1677653"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1125815"},{"type":"PACKAGE","url":"https://github.com/JameelNabbo/Jinja2-Code-execution"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/46386/"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*","cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"15.0"},{"last_affected":"15.0"},{"introduced":"42.3"},{"last_affected":"42.3"}],"source":"CPE_STRING","vendor_product":"opensuse:leap"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}