CVE-2024-56201
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 23, 2024
Updated: Jan 8, 2025
CWE ID 150
Summary
CVE-2024-56201 is a vulnerability affecting Jinja, an extensible templating engine used in various applications. Versions of Jinja on the 3.x branch before 3.1.5 contain a bug that allows an attacker to execute arbitrary Python code if they have control over both the template filename and content. This vulnerability is not dependent on Jinja's sandbox being bypassed. Applications where the template author can choose the filename as well as the template content are at risk. The issue is resolved in Jinja 3.1.5.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.