CVE-2024-22195: Jinja vulnerable to Cross-Site Scripting (XSS)

Published Jan 11, 2024
·
Updated

Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja xmlattr filter can be abused to inject arbitrary HTML attribute keys and values, bypassing the auto escaping mechanism and potentially leading to XSS. It may also be possible to bypass attribute validation checks if they are blacklist-based.

Other sources

Jinja vulnerable to Cross-Site Scripting (XSS)

Microsoft

The xmlattr filter in affected versions of Jinja accepts keys containing spaces. XML/HTML attributes cannot contain spaces, as each would then be interpreted as a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders these in pages that other users see as well, an attacker could use this to inject other attributes and perform XSS. Note that accepting keys as user input is not common or a particularly intended use case of the xmlattr filter, and an application doing so should already be verifying what keys are provided regardless of this fix.

GitHub

Affected Software

21 affected componentsFixes available
debian/jinja2<=2.10-2, <=2.11.3-1, <=3.1.2-1
2.10-2+deb10u13.1.3-1
ubuntu/jinja2<2.10-1ubuntu0.18.04.1+
2.10-1ubuntu0.18.04.1+
ubuntu/jinja2<2.10.1-2ubuntu0.2
2.10.1-2ubuntu0.2
ubuntu/jinja2<3.0.3-1ubuntu0.1
3.0.3-1ubuntu0.1
ubuntu/jinja2<3.1.2-1ubuntu0.23.10.1
3.1.2-1ubuntu0.23.10.1
ubuntu/jinja2<3.1.2-1ubuntu1
3.1.2-1ubuntu1
ubuntu/jinja2<2.7.2-2ubuntu0.1~
2.7.2-2ubuntu0.1~
ubuntu/jinja2<2.8-1ubuntu0.1+
2.8-1ubuntu0.1+
palletsprojects Jinja<3.1.3
pip/jinja2<3.1.3
3.1.3
F5 Traffix SDC=5.1.0
5.2.0
redhat/jinja2<3.1.3
3.1.3
Microsoft cbl2 nodejs18 18.20.3-5
Microsoft azl3 nodejs 20.14.0-8
Microsoft azl3 python-jinja2 3.1.2-3
Microsoft cbl2 nodejs18 18.20.3-5
Microsoft cbl2 python-jinja2 3.0.3-7
Microsoft azl3 nodejs 20.14.0-1
Microsoft azl3 python-jinja2 3.1.2-2
Microsoft cbl2 nodejs18 18.20.3-3
Microsoft cbl2 python-jinja2 3.0.3-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/jinja2 to a version that resolves this vulnerability.

    Fixed in 2.10-2+deb10u1Fixed in 3.1.3-1
  2. Upgrade

    Upgrade ubuntu/jinja2 to a version that resolves this vulnerability.

    Fixed in 2.10-1ubuntu0.18.04.1+
  3. Upgrade

    Upgrade ubuntu/jinja2 to a version that resolves this vulnerability.

    Fixed in 2.10.1-2ubuntu0.2
  4. Upgrade

    Upgrade ubuntu/jinja2 to a version that resolves this vulnerability.

    Fixed in 3.0.3-1ubuntu0.1
  5. Upgrade

    Upgrade ubuntu/jinja2 to a version that resolves this vulnerability.

    Fixed in 3.1.2-1ubuntu0.23.10.1
  6. Upgrade

    Upgrade ubuntu/jinja2 to a version that resolves this vulnerability.

    Fixed in 3.1.2-1ubuntu1
  7. Upgrade

    Upgrade ubuntu/jinja2 to a version that resolves this vulnerability.

    Fixed in 2.7.2-2ubuntu0.1~
  8. Upgrade

    Upgrade ubuntu/jinja2 to a version that resolves this vulnerability.

    Fixed in 2.8-1ubuntu0.1+
  9. Upgrade

    Upgrade pip/jinja2 to a version that resolves this vulnerability.

    Fixed in 3.1.3
  10. Upgrade

    Upgrade F5 Traffix Systems Signaling Delivery Controller to a version that resolves this vulnerability.

    Fixed in 5.2.0
  11. Upgrade

    Upgrade redhat/jinja2 to a version that resolves this vulnerability.

    Fixed in 3.1.3
  12. Upgrade

    Upgrade jinja to a version that resolves this vulnerability.

    Fixed in 3.1.3Patch GHSA-h5c8-rqwp-cp95
  13. Configuration

    If your application uses the Jinja `xmlattr` filter with user-controlled input, ensure it does not accept user input as attribute *keys* (and prevent keys containing spaces), because the `xmlattr` filter in affected versions accepts keys with spaces and can be abused to inject arbitrary HTML attributes/values, bypassing auto escaping and potentially leading to XSS.

    Jinja (xmlattr filter) Keys passed to xmlattr filter = Do not accept user-supplied attribute keys (especially keys containing spaces)

Event History

Jan 11, 2024
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·10:25 AM
DescriptionSeverityAffected Software
Advisory Published
via GitHub·03:20 PM
Jan 17, 2024
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
SeverityAffected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Feb 2, 2024
Data Sourced
via Launchpad·05:41 PM
Description
Sep 30, 2024
Advisory Published
via F5·04:55 PM
Jan 30, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-22195?

The severity of CVE-2024-22195 is categorized as high due to the potential for Cross-Site Scripting (XSS) attacks.

2

How do I fix CVE-2024-22195?

To fix CVE-2024-22195, update your Jinja2 version to at least 3.1.3 or the specific patched versions for your operating system.

3

What vulnerability does CVE-2024-22195 exploit?

CVE-2024-22195 exploits a flaw in the Jinja templating engine that allows the injection of arbitrary HTML attributes leading to XSS.

4

Which software is affected by CVE-2024-22195?

CVE-2024-22195 affects Jinja2 versions below 3.1.3 and various products including IBM QRadar SIEM and F5 Traffix SDC.

5

What is the potential impact of CVE-2024-22195 on web applications?

The potential impact of CVE-2024-22195 on web applications includes the ability for attackers to inject malicious scripts into web pages viewed by users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203