USN-6599-1: Jinja2 vulnerabilities
Yeting Li discovered that Jinja incorrectly handled certain regex. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-28493) It was discovered that Jinja incorrectly handled certain HTML passed with xmlatter filter. An attacker could inject arbitrary HTML attributes keys and values potentially leading to XSS. (CVE-2024-22195)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6599-1?
USN-6599-1 addresses a denial of service vulnerability identified in Jinja that could be exploited by attackers.
How do I fix USN-6599-1?
To resolve USN-6599-1, upgrade to the recommended package versions of python3-jinja2 or python-jinja2 as specified in the advisory.
Which versions of Ubuntu are affected by USN-6599-1?
USN-6599-1 affects Ubuntu 14.04 LTS, 16.04 LTS, 18.04 LTS, and 20.04 LTS.
What is Jinja and why is USN-6599-1 important?
Jinja is a templating engine for Python, and the vulnerabilities addressed in USN-6599-1 may allow denial of service attacks, impacting application availability.
Who discovered the vulnerability leading to USN-6599-1?
The vulnerability that led to USN-6599-1 was discovered by Yeting Li.