Information on source package jinja2

Available versions

ReleaseVersion
jessie2.7.3-1+deb8u1
stretch2.8-1+deb9u1
buster2.10-2+deb10u1
bullseye2.11.3-1
bookworm3.1.2-1
trixie3.1.3-1
sid3.1.3-1

Open issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2024-34064vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerable (no DSA)vulnerablevulnerableJinja is an extensible templating engine. The `xmlattr` filter in affe ...
CVE-2024-22195fixedfixedfixedvulnerable (no DSA)vulnerable (no DSA)fixedfixedJinja is an extensible templating engine. Special placeholders in the ...
CVE-2020-28493vulnerable (no DSA)vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedfixedThis affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDo ...
CVE-2019-10906vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedfixedfixedIn Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape ...
CVE-2016-10745vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedfixedfixedIn Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

Open unimportant issues

BugjessiestretchbusterbullseyebookwormtrixiesidDescription
CVE-2019-8341vulnerablevulnerablevulnerablevulnerablevulnerablevulnerablevulnerableAn issue was discovered in Jinja2 2.10. The from_string function is pr ...

Resolved issues

BugDescription
CVE-2014-1402The default configuration for bccache.FileSystemBytecodeCache in Jinja ...
CVE-2014-0012FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create tempo ...

Security announcements

DSA / DLADescription
ELA-1048-1jinja2 - security update
DLA-3715-1jinja2 - security update

Search for package or bug name: Reporting problems