In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
References
Information
Published : 2019-04-07 00:29
Updated : 2020-08-24 17:37
NVD link : CVE-2019-10906
Mitre link : CVE-2019-10906
JSON object : View
Products Affected
fedoraproject
- fedora
palletsprojects
- jinja
CWE
