In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
The sandbox is used to restrict what code can be evaluated when rendering untrusted, user-provided templates. Due to the way string formatting works in Python, the str.format_map method could be used to escape the sandbox.
This issue was previously addressed for the str.format method in Jinja 2.8.1, which discusses the issue in detail. However, the less-common str.format_map method was overlooked. This release applies the same sandboxing to both methods.
If you cannot upgrade Jinja, you can override the is_safe_attribute method on the sandbox and explicitly disallow the format_map method on string objects.
| Score | Percentile |
|---|---|
| 3.48% | 87.50% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 8.6 | 3.0 | — |
|
| 7.7 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-462w-v97r-4m45 ↗ |
| CVE | CVE-2019-10906 ↗ |
| CWE id | Name |
|---|---|
| CWE-693 | Protection Mechanism Failure |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| pip | Jinja2 | < 2.10.1 | 2.10.1 | — |